
CiscoCertified CyberOps Associate
Domain 5Objective 11
5.11 Describe the Relationship of SOC Metrics to Scope Analysis (time to Detect, Time to Contain, Time to Respond, Time to Control) 200-201 Practice Questions (Page 4)
Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
7concepts
15%of the exam
Questions 16–20
- 16
Why is it important to consider SOC metrics in the context of scope analysis?
Select an answer first - 17
A SOC team is reviewing a security incident. The initial compromise occurred at 08:00, but the SOC did not detect it until 11:00. The response team began containment at 11:30. The SOC manager wants to improve the team's ability to reduce the time between compromise and detection. Which metric should the manager focus on improving?
Select an answer first - 18
A SOC analyst is investigating a potential insider threat. The analyst is asked to determine whether any employees accessed sensitive files outside of business hours. The analyst limits the investigation to the file server logs and the authentication logs for the last 30 days. What is the analyst doing?
Select an answer first - 19
After detecting a malware outbreak at 13:00, the SOC team immediately began investigating. However, due to a lack of clear procedures, the team did not start containment actions until 15:00. The SOC manager wants to reduce the delay between detection and the start of response actions. Which metric should be tracked and improved?
Select an answer first - 20
Which scenario best illustrates a long time to detect (TTD)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.