Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 5Objective 5

5.5 Map the Organization Stakeholders Against the NIST IR Categories (CMMC, NIST.SP800-61) 200-201 Practice Questions (Page 1)

Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
7concepts
15%of the exam

Questions 1–5

  1. 1expert · hard

    A multinational corporation has just completed a ransomware incident that affected its European and Asian data centers. The incident response team lead wants to conduct a post-incident review. The legal team insists on including a discussion of regulatory notification timelines, while the SOC manager wants to focus on technical detection gaps. The CISO has limited time and wants the meeting to produce actionable improvements. Which approach best balances these competing interests?

    Select an answer first
  2. 2foundation · easy

    After an incident is contained, which stakeholder is responsible for restoring affected systems to a known good state and verifying they are operational?

    Select an answer first
  3. 3expert · hard

    A financial institution's SOC detects a series of failed login attempts followed by a successful login from an unusual geographic location. The SOC analyst suspects a compromised account. The threat intelligence team has no prior knowledge of the source IP. The CISO wants to avoid a false positive that could disrupt the user's work. Which approach best balances the need for analysis with the risk of disruption?

    Select an answer first
  4. 4expert · hard

    After a major security incident, a company's incident response team lead wants to conduct a lessons-learned meeting. The legal department insists that the meeting minutes be protected by attorney-client privilege, while the compliance officer wants the minutes to be shared with all employees to promote security awareness. Which approach best satisfies both concerns?

    Select an answer first
  5. 5application · medium

    A university's SOC detects unusual outbound traffic from a research lab. The analyst suspects a compromised account. According to NIST SP 800-61, which stakeholder should the analyst notify first to begin the Detection and Analysis phase?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.