Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified CyberOps Associate

Domain 5Objective 5

5.5 Map the Organization Stakeholders Against the NIST IR Categories (CMMC, NIST.SP800-61) 200-201 Practice Questions (Page 3)

Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
7concepts
15%of the exam

Questions 11–15

  1. 11application · medium

    A company has just completed the recovery phase of a ransomware incident. The incident response team lead wants to ensure that the organization learns from the incident and improves its response capabilities. Which activity should be performed during the Post-Incident Activity phase?

    Select an answer first
  2. 12expert · hard

    A company has confirmed a ransomware infection on a critical database server. The incident response team lead must decide whether to isolate the server immediately or preserve forensic evidence first. The database contains customer data, and the company has regulatory obligations to report breaches. Which action should the team lead take first?

    Select an answer first
  3. 13application · medium

    A defense contractor that handles CUI is implementing CMMC Level 2 practices. The company wants to ensure that incident response procedures are documented and that the right stakeholders are assigned to each phase. Which approach best aligns with CMMC requirements?

    Select an answer first
  4. 14foundation · easy

    In the Preparation phase of incident response, which stakeholder is responsible for developing and reviewing the incident response plan to ensure it meets regulatory and legal requirements?

    Select an answer first
  5. 15foundation · easy

    Which stakeholder is typically responsible for executing containment actions, such as isolating affected systems from the network, during an incident?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.