Cisco CCNA Cybersecurity (200-201 CCNACBR) · Domain 5 · 15% of exam

Security Policies and Procedures

Drill 20 practice questions focused entirely on Security Policies and Procedures for the Cisco 200-201 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

A SOC analyst is building a network profile to detect anomalies for the corporate LAN. She has already documented total throughput and typical session durations. To complete the profile per common network profiling guidance, she wants to record the set of IP addresses that legitimately generate and receive traffic on the segment. Which network profiling element is she documenting?

Reviewed for accuracy · Report an issue
Question 2 of 20

A security analyst is building a network profile for the corporate environment to help detect anomalous behavior. The analyst has already documented total throughput and address space in use. The team lead asks the analyst to add a metric that captures how long connections typically remain open between internal hosts and external services, so that unusually persistent connections (such as those from a covert channel) can be flagged. Which network profiling element should the analyst measure to satisfy this request?

Reviewed for accuracy · Report an issue
Question 3 of 20

A security analyst is building a network profile for the corporate environment to help detect anomalous behavior. The analyst has already documented which TCP and UDP ports are typically open and which internal hosts communicate with which external destinations. According to NIST guidance on network profiling, which additional element should the analyst capture to establish a baseline of how much data normally flows across the network segment over time?

Reviewed for accuracy · Report an issue
Question 4 of 20

During a review of NIST SP 800-61 concepts, an analyst is categorizing signs of incidents. Their SIEM logs a vulnerability scanner sweeping the organization's external IP range from an unknown source. According to NIST SP 800-61, how should this observation be classified?

Reviewed for accuracy · Report an issue
Question 5 of 20

A CyberOps analyst is helping draft the organization's incident response capability. The team lead emphasizes that before any tools are purchased or procedures written, senior leadership must formally approve funding, define the CSIRT's authority, and endorse the IR policy. In terms of NIST SP 800-61 management concepts, why is securing this executive commitment considered foundational to an effective incident response program?

Reviewed for accuracy · Report an issue
Question 6 of 20

After successfully recovering from a major breach, an incident response team lead is finalizing documentation. During the wrap-up meeting, a junior analyst asks how long the collected logs, disk images, and captured network traffic must be kept. According to NIST SP 800-61, which element of the incident response plan most directly governs this decision?

Reviewed for accuracy · Report an issue
Question 7 of 20

During an incident response investigation, forensic analysis confirms that an internal employee intentionally exfiltrated customer records to a personal cloud account. The incident response coordinator needs to involve the appropriate stakeholder to handle disciplinary action against the employee in accordance with company policy. According to NIST SP 800-61, which stakeholder should the coordinator engage for this task?

Reviewed for accuracy · Report an issue
Question 8 of 20

During a data breach investigation, an organization following NIST SP 800-61 must decide whether disclosure is required under contractual and regulatory obligations, and must review potential liability before the incident is publicly reported. Which stakeholder role should the incident response team primarily engage for this determination?

Reviewed for accuracy · Report an issue
Question 9 of 20

During a confirmed ransomware incident at a hospital, the incident response coordinator is assembling the response team per NIST SP 800-61. A local news outlet has begun contacting the organization, and executives want to ensure that any external messaging about the breach is accurate, consistent, and does not compromise the ongoing investigation. Which stakeholder or team should be assigned responsibility for managing communications with the news outlet and the public?

Reviewed for accuracy · Report an issue
Question 10 of 20

A forensic analyst responding to a live compromised Linux server must collect evidence following NIST SP 800-86 guidance. The system is still powered on and connected to the network. According to the order of volatility, which data source should the analyst prioritize collecting FIRST?

Reviewed for accuracy · Report an issue
Question 11 of 20

A CyberOps analyst is establishing a digital forensics workflow based on NIST SP 800-86. After legally acquiring a suspect's hard drive image, the analyst needs to identify and extract relevant items such as file timestamps and application data before drawing conclusions for the incident report. According to the four-phase forensic process in NIST SP 800-86, which phase is the analyst performing when identifying and extracting these relevant items from the acquired data?

Reviewed for accuracy · Report an issue
Question 12 of 20

A mid-size company is building its digital forensics capability. Following NIST SP 800-86 guidance, the security manager wants to ensure that when an incident occurs, analysts can immediately collect and preserve evidence without delay. Which action BEST reflects the NIST SP 800-86 recommendation for organizational readiness?

Reviewed for accuracy · Report an issue
Question 13 of 20

An analyst confirms that several workstations are infected with a worm that is actively spreading across the internal network. Following NIST SP 800-61, the incident response team first disconnects the affected VLAN to stop the spread, then removes the malware and patches the exploited vulnerability, and finally restores the systems from clean backups and monitors them before returning them to production. Which NIST incident handling phase encompasses ALL of the actions the team performed in this sequence?

Reviewed for accuracy · Report an issue
Question 14 of 20

A SOC analyst receives an automated alert from the SIEM indicating unusual authentication activity. The analyst reviews correlated logs, confirms the activity is malicious rather than a false positive, documents the affected systems, and assigns a severity rating before notifying the incident response lead. According to the NIST SP 800-61 incident response lifecycle, which phase do these analyst actions primarily belong to?

Reviewed for accuracy · Report an issue
Question 15 of 20

Following a ransomware outbreak, an incident response team has removed the malware, rebuilt affected systems, and confirmed normal operations have resumed. The team now holds a meeting to document what happened, evaluate how well their procedures worked, and identify improvements to detection tooling and staff training. According to the NIST SP 800-61 incident response lifecycle, which phase does this meeting represent?

Reviewed for accuracy · Report an issue
Question 16 of 20

A newly hired CyberOps analyst is reviewing the organization's incident response program, which is modeled on NIST SP 800-61. She notices that before any incident occurs, the team has already deployed a centralized log aggregation platform, created jump bags with forensic tools, established out-of-band communication channels, and trained staff on their roles. Which phase of the NIST incident response life cycle do these activities belong to?

Reviewed for accuracy · Report an issue
Question 17 of 20

During a data classification review, a SOC analyst is cataloging the types of protected data traversing the corporate network. The engineering team stores proprietary source code, patented product design schematics, and internal research documents on a shared server. Which category of protected data best describes these assets?

Reviewed for accuracy · Report an issue
Question 18 of 20

A SOC analyst at a hospital is reviewing an exfiltration alert. The captured data set contains patient names paired with their diagnosis codes, prescribed medications, and treatment dates. Under data protection classifications, which category best describes this specific data?

Reviewed for accuracy · Report an issue
Question 19 of 20

During a data-classification review, a CyberOps analyst captures a database export traversing the internal network. The record set contains employee full names paired with Social Security numbers, home addresses, and dates of birth. According to standard data-protection categories, how should this data be classified?

Reviewed for accuracy · Report an issue
Question 20 of 20

A security analyst is building a server profile for a company's internal application server so that future deviations can be detected. The analyst has already documented the server's listening ports and its normal user accounts. According to server profiling practices, which additional element should the analyst document to identify unauthorized or anomalous programs that may later run on the host?

Reviewed for accuracy · Report an issue

More 200-201 practice

Keep going with the other Cisco CCNA Cybersecurity (200-201 CCNACBR) domains, or take a full timed mock exam.

← Back to 200-201 overview