
CiscoCertified CyberOps Associate
Domain 5Objective 5
5.5 Map the Organization Stakeholders Against the NIST IR Categories (CMMC, NIST.SP800-61) 200-201 Practice Questions (Page 6)
Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
15%of the exam
Questions 26–30
- 26
Which stakeholder group is primarily responsible for monitoring network traffic and analyzing alerts to detect potential security incidents?
Select an answer first - 27
A regional bank is updating its incident response plan. The CISO wants to ensure that before any incident occurs, the organization has defined escalation paths, trained staff, and established communication channels with external parties such as law enforcement and the managed security service provider. During which NIST SP 800-61 lifecycle phase should these activities be formalized, and which stakeholder group is primarily responsible for driving them?
Select an answer first - 28
A defense contractor is preparing for a CMMC Level 2 assessment. The assessor asks how the organization ensures that incident response procedures are tested and that personnel are trained. Which CMMC practice directly addresses this requirement, and which stakeholder is typically responsible for coordinating the training?
Select an answer first - 29
A manufacturing company has confirmed a ransomware infection on a production server. The incident response plan requires isolating the host, preserving evidence, and restoring from backups. Which stakeholder group should lead the containment action of disconnecting the server from the network?
Select an answer first - 30
A defense contractor is implementing CMMC Level 2 and must map its incident response stakeholders to NIST SP 800-61 categories. The contractor has a small IT team where the same person often serves as both SOC analyst and system administrator. The CISO wants to ensure that CMMC practice IR.2.092 is satisfied without creating a conflict of interest in incident response. Which approach best addresses this constraint?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.