
CiscoCertified CyberOps Associate
Domain 5Objective 3
5.3 Apply the Incident Handling Process Such as NIST.SP800-61 to an Event 200-201 Practice Questions (Page 6)
Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
8concepts
15%of the exam
Questions 26–29
- 26
In an incident response team, which role is typically responsible for coordinating the response efforts and ensuring that the team follows the incident handling process?
Select an answer first - 27
A security team is responding to a ransomware incident. The team has isolated the affected systems and is now preparing to eradicate the malware. Which action is part of the Eradication phase?
Select an answer first - 28
Which activity is part of the recovery phase after an incident has been eradicated?
Select an answer first - 29
During an incident, a security team decides to isolate an infected workstation from the network. Which containment strategy does this action represent?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 200-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.