
CiscoCertified CyberOps Associate
Domain 5Objective 11
5.11 Describe the Relationship of SOC Metrics to Scope Analysis (time to Detect, Time to Contain, Time to Respond, Time to Control) 200-201 Practice Questions (Page 2)
Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
7concepts
15%of the exam
Questions 6–10
- 6
After a data breach, a SOC team detects the intrusion at 08:00, contains the affected systems by 09:00, and fully restores administrative control and data integrity by 11:00. Which metric best reflects the total time from detection to regaining full control?
Select an answer first - 7
What does the SOC metric 'time to detect' (TTD) measure?
Select an answer first - 8
A SOC manager is comparing two incidents. Incident A had a TTC of 30 minutes and a TTCO of 2 hours. Incident B had a TTC of 2 hours and a TTCO of 3 hours. Which incident demonstrates better containment performance?
Select an answer first - 9
A SOC manager is evaluating the effectiveness of the incident response process after a phishing campaign. The manager notices that TTD has been consistently high, but TTR and TTC are within acceptable targets. What does this pattern indicate about the SOC's performance?
Select an answer first - 10
Which statement best defines SOC metrics?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.