
CiscoCertified CyberOps Associate
Domain 5Objective 6
5.6 Describe Concepts as Documented in NIST.SP800-86 200-201 Practice Questions (Page 1)
Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
4concepts
15%of the exam
Questions 1–5
- 1
A forensic analyst is about to image a hard drive from a computer that was used in a fraud case. The analyst wants to ensure that the imaging process does not modify the original drive. Which tool or technique should be used?
Select an answer first - 2
What is the primary purpose of maintaining a chain of custody for digital evidence?
Select an answer first - 3
An incident responder is investigating a possible data breach on a laptop. The laptop is currently on, and the responder needs to collect evidence. Which of the following is an example of volatile data that should be collected immediately?
Select an answer first - 4
Which method is commonly used to verify that digital evidence has not been altered after collection?
Select an answer first - 5
A security analyst is investigating a suspected data exfiltration on a user's laptop. The laptop is currently running, and the analyst has remote access. Which of the following is the most important volatile data to collect before the laptop is disconnected from the network?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.