Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 5Objective 2

5.2 Describe the Elements in an Incident Response Plan as Stated in NIST.SP800-61 200-201 Practice Questions (Page 1)

Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)

59questions here
12free pages
12concepts
15%of the exam

Questions 1–5

  1. 1application · medium

    A security analyst detects a ransomware outbreak on a file server. The incident response plan calls for isolating affected hosts immediately, but the legal department requires that forensic evidence be preserved. Which action best balances containment with evidence preservation?

    Select an answer first
  2. 2expert · hard

    After a major incident, the incident response team is preparing the post-incident report. The legal department wants to include detailed technical findings, while the public relations team wants to release a summary to the public. The team must satisfy both. Which approach is most appropriate?

    Select an answer first
  3. 3application · medium

    A new incident response manager is reviewing the organization's incident response plan. The manager notices that the plan does not identify who is responsible for making decisions about law enforcement involvement. According to NIST SP 800-61, which element is MISSING from the plan?

    Select an answer first
  4. 4expert · hard

    A company is developing its incident response plan. Management wants to ensure that the plan is actionable and that team members know what to do for different types of incidents. The team has limited time and resources. What is the MOST efficient approach to meet this requirement?

    Select an answer first
  5. 5expert · hard

    A ransomware attack is spreading across a company's network. The affected systems include a critical database that cannot be offline for more than 15 minutes without causing significant business loss. The incident response team has a choice: isolate the database immediately (which will cause downtime) or leave it online to maintain operations while attempting to stop the spread. Which approach best aligns with NIST SP 800-61 guidance?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.