Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 5Objective 11

5.11 Describe the Relationship of SOC Metrics to Scope Analysis (time to Detect, Time to Contain, Time to Respond, Time to Control) 200-201 Practice Questions (Page 3)

Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
7concepts
15%of the exam

Questions 11–15

  1. 11application · medium

    A SOC manager wants to evaluate how well the team detects incidents that occur outside of normal business hours. The team's scope analysis for this evaluation includes only incidents that occur between 18:00 and 06:00. Which metric should the manager focus on to assess this specific aspect of performance?

    Select an answer first
  2. 12expert · hard

    A SOC manager is reviewing the following incident metrics for the past quarter: - Average TTD: 6 hours - Average TTR: 15 minutes - Average TTC: 2 hours - Average TTCO: 8 hours The manager notices that TTD is high, but TTR is very low. The manager also sees that TTCO is significantly higher than TTC. The SOC has a limited budget and must decide where to focus improvements. Which conclusion is most justified?

    Select an answer first
  3. 13application · medium

    An incident response team detected a breach at 16:00. They contained the affected systems by 17:00, but it took until 20:00 to regain full administrative control and ensure the attacker no longer had access. The SOC manager wants to report the time to control (TTCO). What is the TTCO?

    Select an answer first
  4. 14application · medium

    A SOC analyst is assigned to investigate a potential data breach. The analyst is told to focus only on the systems that store customer payment data and to determine whether any unauthorized access occurred. What is the analyst performing?

    Select an answer first
  5. 15foundation · easy

    Which activity is a key part of scope analysis in incident response?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.