
CiscoCertified CyberOps Associate
Domain 1Objective 4
1.4 Compare Security Concepts 200-201 Practice Questions (Page 8)
Part of the 1.0 Security Concepts domain, which accounts for 20% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 1–1 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
7concepts
20%of the exam
Questions 36–40
- 36
A risk assessment team is conducting a risk assessment for a healthcare organization. The team has identified that the organization's patient records system is a critical asset. The system has a known vulnerability that could allow unauthorized access to patient data. The team has determined that the likelihood of exploitation is high because the vulnerability is publicly known and the system is internet-facing. The impact of a breach is also high because of regulatory fines and reputational damage. The team is now at the risk evaluation step. Which action should the team take next?
Select an answer first - 37
A regional bank is evaluating the risk of a new mobile banking feature. The feature will store customer financial data in a new cloud database. The bank's risk team identifies that a misconfigured database could expose customer records, and the likelihood of misconfiguration is rated as medium. The impact of a data breach is rated as high because of regulatory fines and reputational damage. The bank's risk appetite allows for medium-risk projects to proceed with additional controls. Which action best aligns with the bank's risk appetite?
Select an answer first - 38
How does an exploit relate to a vulnerability?
Select an answer first - 39
A small e-commerce company hosts its website on a single server. A risk assessment identifies that a denial-of-service (DoS) attack could take the site offline, causing significant revenue loss. The company has a limited budget and cannot afford a full high-availability architecture. The management decides to purchase a DoS protection service from a third-party provider. This decision is an example of which risk treatment strategy?
Select an answer first - 40
Which risk management strategy involves purchasing an insurance policy to cover potential losses from a security incident?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to 200-201
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.