
CiscoCertified CyberOps Associate
Domain 1Objective 6
1.6 Compare Access Control Models 200-201 Practice Questions (Page 2)
Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 30 practice questions to prepare you well beyond it. (estimate)
30questions here
6free pages
8concepts
20%of the exam
Questions 6–10
- 6
An organization wants to ensure that only authenticated users can access its VPN, that each user is limited to the resources their role permits, and that all login attempts are recorded for security review. Which combination of AAA components addresses these requirements?
Select an answer first - 7
What is a key advantage of Role-Based Access Control (RBAC) over Discretionary Access Control (DAC)?
Select an answer first - 8
In Role-Based Access Control (RBAC), how are permissions assigned to users?
Select an answer first - 9
A software company wants to simplify permission management by assigning access based on job functions such as developer, tester, and manager. The security team will centrally define which permissions each role has, and employees will be assigned to roles. Which access control model should be implemented?
Select an answer first - 10
A government agency is migrating from a legacy system that used DAC, where each file owner set permissions. The new system must enforce a classification policy (e.g., 'Top Secret' files can only be read by users with a 'Top Secret' clearance) and prevent users from downgrading file classifications. However, the agency also needs to allow project leads to grant access to their own project files for collaboration. Which approach best satisfies both requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.