
CiscoCertified CyberOps Associate
Domain 5Objective 2
5.2 Describe the Elements in an Incident Response Plan as Stated in NIST.SP800-61 200-201 Practice Questions (Page 10)
Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
12concepts
15%of the exam
Questions 46–50
- 46
Why is coordination with an Information Sharing and Analysis Center (ISAC) valuable during incident response?
Select an answer first - 47
Which of the following is a key preparation activity for incident response?
Select an answer first - 48
A company has a documented procedure for handling malware infections. During a new malware incident, the analyst notices that the procedure does not cover a new variant that disables the antivirus agent. What should the analyst do according to NIST SP 800-61 guidance?
Select an answer first - 49
A company's incident response plan is being reviewed. The plan includes detailed technical procedures, but it does not define the authority of the incident response team to take actions such as disconnecting systems or contacting external parties. What is the MOST likely consequence of this gap?
Select an answer first - 50
During an incident, a system administrator discovers a compromised server and begins deleting files to stop the attack. The incident response team later finds that critical evidence was destroyed. Which element of the incident response plan would have prevented this if it had been followed?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.