Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 5Objective 11

5.11 Describe the Relationship of SOC Metrics to Scope Analysis (time to Detect, Time to Contain, Time to Respond, Time to Control) 200-201 Practice Questions (Page 5)

Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)

25questions here
5free pages
7concepts
15%of the exam

Questions 21–25

  1. 21application · medium

    During a ransomware incident, the SOC detected the attack at 14:00. The incident response team isolated the affected hosts at 15:30, preventing further spread. The SOC manager asks for the time to contain (TTC). What is the TTC?

    Select an answer first
  2. 22foundation · easy

    What is scope analysis in the context of a SOC investigation?

    Select an answer first
  3. 23foundation · easy

    Which scenario best illustrates regaining control over affected systems?

    Select an answer first
  4. 24application · medium

    An organization's SOC detected a malware infection on a critical server at 10:00. The incident response team was notified and began containment actions at 10:45. The SOC manager wants to report the time to respond (TTR) for this incident. What is the TTR?

    Select an answer first
  5. 25foundation · easy

    What is the primary purpose of SOC metrics?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to 200-201

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.