
CiscoCertified CyberOps Associate
Domain 5Objective 5
5.5 Map the Organization Stakeholders Against the NIST IR Categories (CMMC, NIST.SP800-61) 200-201 Practice Questions (Page 8)
Part of the 5.0 Security Policies and Procedures domain, which accounts for 15% of the 200-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)
44questions here
9free pages
7concepts
15%of the exam
Questions 36–40
- 36
A defense contractor is pursuing CMMC Level 2 certification. The company has a small IT staff: one IT manager, two system administrators, and one part-time SOC analyst. The CISO wants to map stakeholders to the NIST SP 800-61 incident response categories. The company also handles CUI and must demonstrate that incident response practices are documented and followed. Which stakeholder mapping best balances CMMC Level 2 requirements with the limited staff?
Select an answer first - 37
During the Preparation phase of incident response, which stakeholder is primarily responsible for ensuring that the incident response team has the necessary budget and authority to act?
Select an answer first - 38
A defense contractor is implementing CMMC Level 2 and must map stakeholders to incident response categories. The company has a small IT team and cannot afford a dedicated incident response team. The CISO wants to ensure that the mapping is compliant and that the company can demonstrate process maturity. Which approach is most appropriate?
Select an answer first - 39
A manufacturing company has confirmed that a workstation is infected with ransomware. The incident response team lead has decided to isolate the host from the network, remove the malware, and restore the system from a known-good backup. Which stakeholders are primarily responsible for executing these actions?
Select an answer first - 40
A financial services firm has confirmed a malware infection on several workstations. The incident response plan calls for eradicating the malware and recovering the systems. Which stakeholder group is primarily responsible for eradicating the malware from the affected workstations?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-201” is a trademark of its owner, used for identification only.