Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 5Objective 4

5.4 Map Elements to These Steps of Analysis Based on the NIST.SP800-61 200-201 Practice Questions (Page 3)

Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
4concepts
15%of the exam

Questions 11–15

  1. 11application · medium

    A malware infection has been detected on a critical database server. The server cannot be taken offline because it supports a live production application. According to NIST.SP800-61, which containment strategy is most appropriate in this situation?

    Select an answer first
  2. 12application · medium

    A security incident was resolved, and the incident response team is writing a report. The report includes a timeline of events, actions taken, and root cause. According to NIST.SP800-61, what additional element should be included in the post-incident report?

    Select an answer first
  3. 13application · medium

    After a ransomware incident, the CSIRT successfully contained the threat and restored systems from backups. The team is now meeting to discuss what went well and what could be improved. According to NIST.SP800-61, which output is the MOST important to produce from this meeting?

    Select an answer first
  4. 14application · medium

    A mid-sized company is building its first incident response capability. The security manager has just received approval to purchase a SIEM platform and endpoint detection tools. The CSIRT team has been assembled, but no formal procedures exist yet. According to NIST.SP800-61, which activity should the team complete FIRST to ensure the new tools and team are effective?

    Select an answer first
  5. 15application · medium

    A company is about to deploy a new incident response plan. The plan includes roles, escalation procedures, and tool lists. According to NIST.SP800-61, what additional preparation activity should the company perform before an incident occurs?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.