
CiscoCertified CyberOps Associate
Domain 5Objective 6
5.6 Describe Concepts as Documented in NIST.SP800-86 200-201 Practice Questions (Page 4)
Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
4concepts
15%of the exam
Questions 16–20
- 16
An analyst is responding to a ransomware incident on a critical server. The server is still running, but the analyst knows that the system may be shut down by the IT team soon. Which data should the analyst collect first?
Select an answer first - 17
An incident response team is responding to a suspected advanced persistent threat on a critical database server. The server is running, but the team has been told that the server must be patched and rebooted within the hour to meet a business SLA. The team needs to collect evidence that will be used in a legal case. Which approach best balances the need to collect evidence with the business requirement?
Select an answer first - 18
A forensic examiner is collecting evidence from a server that was compromised. The examiner wants to ensure that the evidence is not accidentally modified during the collection process. Which tool or technique should be used?
Select an answer first - 19
A security analyst is responding to an incident on a server that is part of a critical production environment. The server is running, but the analyst has been instructed to minimize downtime. The analyst needs to collect evidence that will be used for internal investigation, not for court. Which action is the most appropriate?
Select an answer first - 20
An incident responder is investigating a suspected insider threat on a user's workstation. The workstation is running, but the user is about to log off, which may terminate critical processes. The responder has remote access and must collect evidence without alerting the user. Which action is the most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.