
CiscoCertified CyberOps Associate
Domain 5Objective 2
5.2 Describe the Elements in an Incident Response Plan as Stated in NIST.SP800-61 200-201 Practice Questions (Page 4)
Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 59 practice questions to prepare you well beyond it. (estimate)
59questions here
12free pages
12concepts
15%of the exam
Questions 16–20
- 16
Which phase of incident handling involves identifying that an incident has occurred and determining its scope?
Select an answer first - 17
Which data source is commonly used to detect and analyze potential security incidents?
Select an answer first - 18
A malware infection is confirmed on a single user workstation. The workstation is not critical to business operations. According to NIST SP 800-61, which containment strategy is most appropriate for this situation?
Select an answer first - 19
After a phishing incident is contained and eradicated, the incident response team holds a meeting to discuss what went well and what could be improved. They also update the playbook for phishing response. Which phase of incident handling does this represent?
Select an answer first - 20
A small company is building its incident response capability. Management wants to ensure that the team has clear authority to act during an incident and that response activities are consistent across different types of incidents. Which element should be established FIRST?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.