Be able to place a scenario in the correct NIST SP 800-61 phase, pick containment that preserves volatile evidence, and describe forensic integrity steps. The single most important thing: never destroy volatile data before capturing it, and document chain of custody.
Start practicing
Security Policies and Procedures — choose a session length
Free · No account required
Domain overview
This domain covers incident response per NIST SP 800-61 (preparation, detection and analysis, containment/eradication/recovery, post-incident), plus policy documents such as AUP, data classification, and evidence handling. Questions are scenario-based: you identify the correct IR phase, choose containment actions that preserve volatile data, and apply chain-of-custody and forensic integrity practices.
Exam objectives
Mapping triage and alert validation to the NIST SP 800-61 detection and analysis phase
Ordering containment, eradication, and recovery activities during a live incident
Recognizing AUP content: acceptable use, monitoring, and consequences of violations
Preserving evidence via write blockers, hashing, and documented chain of custody
Confusing containment with eradication or recovery; powering off a host is containment but destroys volatile memory evidence.
Treating triage as preparation; initial alert validation and scoping belong to detection and analysis.
Assuming an AUP grants technical controls; it states user expectations and sanctions, not firewall or EDR configuration.
Click any question to see the full explanation and answer options, or start a focused practice session above.
During which phase of the NIST SP 800-61 Rev 2 incident response process should an organization develop and exercise the incident response plan?
2A security analyst receives an alert from the SIEM indicating a large number of failed login attempts from an external IP address targeting a user account. According to the incident response process, what should be the analyst's first action?
3An organization's incident response team has identified a malware infection on a critical server. They need to collect evidence for potential legal action. Which of the following is the most important step to ensure the admissibility of the evidence?
4Which role in the incident response process is primarily responsible for determining the business impact of an incident and making strategic decisions?
5An employee is suspected of using company resources to access inappropriate websites. Which security policy most directly addresses this behavior?
6During a risk assessment, a company identifies that the annualized loss expectancy (ALE) for a specific threat is $50,000. The cost to implement a mitigation control is $30,000 with an annual maintenance cost of $5,000. According to risk management principles, what is the most appropriate risk treatment option?
7A SOC analyst at Tier 1 receives an alert for a known malware signature. After initial investigation, the analyst finds that the alert is a false positive caused by an outdated signature. What should the analyst do next?
8Which threat intelligence sharing standard defines a language and format for representing structured threat information, such as indicators and campaigns?
9During the containment phase of an incident, the IR team decides to power off a compromised server to prevent further damage. However, they later realize that this action may have destroyed volatile evidence. According to best practices, what should the team have done instead?
10A company's security policy requires that all data classified as 'Confidential' must be encrypted at rest and in transit. This requirement is part of which policy?
11Which SOC tier is responsible for threat hunting and advanced forensic analysis?
12An incident handler needs to preserve a hard drive from a compromised system. Which two actions are essential to maintain the integrity of the evidence?
13Which of the following are responsibilities of the legal counsel role during incident response? (Choose two.)
14An organization is implementing a threat intelligence sharing program. They want to exchange both structured indicators and full reports with other members of their ISAC. Which combination of standards/protocols should they choose? (Choose two.)
15After resolving a security incident, the IR team conducts a lessons learned meeting. Which of the following are typical outputs of this post-incident activity? (Choose three.)
16An organization is implementing an AUP that prohibits personal use of corporate resources. However, an employee uses a company laptop to access personal email, which leads to a malware infection. Which policy violation is most directly implicated?
17In the NIST SP 800-61 Rev 2 incident response process, which phase involves documenting lessons learned and updating the incident response plan?
18A SOC analyst is investigating a suspected data exfiltration. The analyst needs to preserve evidence from a compromised workstation. Which of the following is the CORRECT procedure to ensure evidence integrity?
19During a security incident, the CISO decides to contain a compromised server by isolating it from the network. Which role is primarily responsible for making this containment decision based on business impact?
20Which of the following is the CORRECT order of the NIST SP 800-61 Rev 2 incident response lifecycle phases?
21An organization is conducting a risk assessment and assigns a monetary value to potential losses. Which risk assessment method is being used?
22A SOC Tier 2 analyst is investigating an alert that was escalated by Tier 1. The analyst needs to perform deeper correlation and malware analysis. Which of the following actions is most appropriate for Tier 2?
23Which organization facilitates threat intelligence sharing among members in a specific sector, such as finance or healthcare?
24During the Containment, Eradication, and Recovery phase, the incident response team collects evidence from a compromised system. Which document is used to record the chain of custody?
25Which risk treatment option involves taking actions to reduce the likelihood or impact of a risk?
26An organization is required to preserve data that may be relevant to a lawsuit. Which legal process is invoked to prevent destruction of this data?
27A SOC Tier 3 analyst is performing advanced threat analysis. Which TWO activities are typical for this tier?
28During which phase of the NIST SP 800-61 Rev 2 incident response process would the incident response team conduct initial triage and determine whether an event qualifies as an incident?
29A security analyst at a SOC Tier 1 receives an alert about a potential malware infection on a user's workstation. What is the primary responsibility of the Tier 1 analyst in this scenario?
30An organization is implementing a new remote access policy. Which of the following is a key component that should be included in this policy?
31During an incident, a forensic analyst needs to preserve evidence from a compromised hard drive. Which of the following steps is essential to maintain the chain of custody?
32In the context of risk management, which term describes the risk that remains after implementing security controls?
33An organization is developing an Acceptable Use Policy (AUP). Which of the following topics is typically covered in an AUP?
34A security analyst needs to share threat intelligence with other organizations in a standardized, machine-readable format. Which combination of standards should the analyst use?
35During a security incident, the incident handler identifies that the breach involves personally identifiable information (PII) of customers. Which role is primarily responsible for determining if legal notification requirements apply?
36Which risk treatment option involves implementing security controls to reduce the likelihood or impact of a risk?
37A SOC Tier 2 analyst is investigating an alert that was escalated from Tier 1. The analyst suspects the malware is using a new variant of ransomware. What is the most appropriate next step for the Tier 2 analyst?
38An organization is conducting a risk assessment and wants to assign numerical values to the likelihood and impact of risks. Which type of risk assessment is being performed?
39In the NIST SP 800-61 Rev 2 incident response process, which phase involves activities such as performing lessons learned and updating the incident response plan?
40A security analyst is collecting evidence from a compromised system for legal proceedings. Which TWO actions are critical to preserve the integrity of the evidence?
41An organization is implementing a threat intelligence sharing program. Which THREE elements are commonly used standards or platforms for sharing threat intelligence?
42A security analyst is triaging an alert about a user downloading a suspicious file. According to the NIST SP 800-61 Rev 2 incident response process, in which phase does initial triage occur?
43A SOC Tier 1 analyst receives an alert for a potential malware infection. What is the primary responsibility of the Tier 1 analyst?
44An organization has implemented a new password policy requiring 12-character passwords with complexity. Which risk treatment option is this an example of?
45After containing a security incident, the incident response team eradicates the malware and restores systems from clean backups. Which phase of the NIST SP 800-61 Rev 2 process does this represent?
46An organization uses STIX and TAXII to share threat intelligence with an ISAC. What is the purpose of TAXII in this scenario?
47A company's legal counsel is involved in an incident response due to a data breach. What is the primary role of legal counsel during the incident?
48An organization is reviewing its risk management process and identifies a risk with a high probability and high impact. Management decides to stop the activity causing the risk. Which risk treatment option is being applied?
49During an incident investigation, the IR team collects evidence from a compromised server. The evidence must be admissible in court. Which documentation is essential to maintain the chain of custody?
50A SOC Tier 3 analyst is performing threat hunting. Which activity best describes the primary focus of a Tier 3 analyst?
51An organization uses a qualitative risk assessment to evaluate a new vendor. Which characteristic is typical of qualitative risk assessments?
52A security analyst is establishing a data classification policy. Which TWO categories are commonly included in a data classification policy?
53After a security incident, the IR team holds a lessons learned meeting. Which THREE activities are part of the Post-Incident Activity phase?
54A security team is implementing a remote access policy. Which TWO controls should be included to ensure secure remote access?
55During which phase of the NIST SP 800-61 Rev 2 incident response process does an organization develop an incident response plan and assemble a team?
56A security analyst is investigating a potential data breach. They need to preserve evidence for legal proceedings. Which action should the analyst take to ensure the integrity of the data?
57A SOC Tier 2 analyst receives an escalated alert about a potential command-and-control (C2) communication. The analyst needs to correlate network logs with threat intelligence. Which data format and transport protocol pair is specifically designed for standardized threat intelligence sharing?
58Which security policy defines acceptable use of an organization's IT resources, including internet browsing and email?
59During an incident, a SOC Tier 1 analyst identifies a series of failed login attempts from an internal IP address. The analyst escalates the alert. What is the primary role of a Tier 2 analyst in this scenario?
60An incident handler collects a hard drive from a compromised server. To maintain chain of custody, which information must be documented?
61A SOC analyst is investigating a potential malware outbreak. Which THREE actions should the analyst take to preserve evidence? (Select three.)
62Which TWO are components of the NIST SP 800-61 Rev 2 Preparation phase? (Select two.)
63Which TWO are examples of risk treatment options? (Select two.)
64A SOC Tier 1 analyst is processing alerts. Which THREE tasks are typical for a Tier 1 analyst? (Select three.)
65A financial institution must comply with PCI DSS requirements for handling cardholder data. A security administrator is asked to implement the control that directly addresses the requirement to protect stored cardholder data. Which technology should the administrator deploy to meet this specific PCI DSS requirement?
66A retail company is updating its security policy framework and needs to align its security controls with a widely recognized U.S. federal standard. The company wants a publication that provides a comprehensive catalog of security and privacy controls for federal information systems and organizations. Which NIST publication should the security team reference?
67A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. A new marketing campaign document contains strategic pricing information that, if disclosed, could cause competitive harm. According to typical data classification practices, how should this document be classified?
68A security analyst is reviewing the organization's incident response plan. The plan defines several roles, including one responsible for coordinating all incident response activities and serving as the central point of communication. During a recent ransomware incident, this person was responsible for declaring the incident and ensuring that all stakeholders were informed. Which role does this describe?
69A healthcare organization is developing an incident response plan. The security manager wants to ensure that the plan includes a phase where the team practices and tests their response capabilities before an actual incident occurs. According to the NIST incident response lifecycle, which phase involves preparing and preventing incidents through activities like training and exercises?
70A security operations center (SOC) manager is developing a playbook for handling phishing incidents. The playbook must specify the first action an analyst should take upon receiving a reported phishing email. Which action should be performed first according to standard incident response procedures?
71A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. The analyst is asked to classify a document that contains the company's proprietary source code. According to typical data classification standards, which classification level is most appropriate?
72A financial institution is implementing a data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. The security team must ensure that data labeled 'Restricted' receives the highest level of protection, including encryption, strict access controls, and monitoring. Which data classification level is typically subject to the most stringent regulatory requirements and requires the strongest security controls?
73A security manager is drafting a service level agreement (SLA) with a cloud service provider. The SLA must specify the maximum acceptable time for the provider to restore service after a disruption. Which metric should the manager include in the SLA to define this requirement?
74A security analyst is reviewing the organization's security policies and notices that the Acceptable Use Policy (AUP) is outdated. The analyst is asked to identify key elements that should be included in an effective AUP. Which two elements are essential components of an AUP? (Choose two.)
75A security analyst is reviewing the chain of custody form for a laptop seized from an employee suspected of intellectual property theft. The form shows the laptop was collected by the IT manager, transported to a storage room, and later examined by an outside forensics firm. The analyst notices that the form lacks signatures for the transfer between the IT manager and the storage room custodian. What is the most likely impact of this omission on the investigation?
76A new security analyst is reviewing the organization's data classification policy and notices that data labeled 'Restricted' must be encrypted at rest and in transit, while data labeled 'Internal' has no encryption requirement. The analyst asks why the policy distinguishes between these levels. What is the primary purpose of a data classification policy?
77A security analyst is reviewing the organization's security policy framework. The analyst notes that the policy defines the acceptable use of company assets, including computers, networks, and data. Which document typically outlines the rules for employee behavior when using these assets?
78A mid-size healthcare company has completed its annual review of security documentation. The CISO asks the governance team to align the documents into a clear hierarchy, where a single high-level document states the organization's overall security intentions and direction, and all subordinate documents must conform to it. Which document should the governance team treat as the highest-level authority?
79A company is updating its security policy to align with the principle of least privilege. The IT director asks the security analyst to recommend a control that enforces this principle for user access to a financial application. Which control should the analyst recommend?
80A security manager is drafting an incident response policy and wants to ensure that the organization can legally monitor employee communications during an investigation. The manager asks the legal team what element must be included in the employee handbook and policy documents to support this capability. Which element is most critical?
81A security analyst is reviewing the organization's incident response plan and notices that it does not specify how to handle a situation where a zero-day vulnerability is exploited before a patch is available. The analyst wants to recommend a proactive measure that aligns with the NIST SP 800-61 revision 2 and the CyberOps Associate curriculum. Which of the following should the analyst recommend?
82A financial services firm must comply with regulations covering cardholder data. The security team is mapping its controls to the PCI DSS framework and wants to confirm that the framework's requirements are being met before an upcoming assessment. Which statement best describes what PCI DSS provides to the organization?
83A SOC manager is drafting the organization's incident response plan and wants to align it with the NIST SP 800-61 Rev. 2 lifecycle so that phases are clearly defined for auditors. Which sequence correctly represents the four phases of the incident response lifecycle as described in NIST SP 800-61 Rev. 2?
84A security analyst discovers that a former employee's user account remains active 45 days after termination, and audit logs show that the account was used to access a file server twice in the past week. Which element of the access control lifecycle was MOST directly violated?
85A security analyst is reviewing the organization's business continuity plan (BCP) after a recent power outage disrupted operations. The analyst notes that the plan includes an alternate processing site and a backup generator but lacks other key components. Which TWO additional elements should the analyst recommend including to improve the BCP? (Choose two.)
86A security manager is updating the organization's data classification policy. The policy must align with the CyberOps Associate curriculum and ensure that data handling procedures are consistent. The manager proposes that data classified as 'Public' should still be encrypted when stored on internal servers. Which principle should guide the manager's decision?
87A hospital's security team is updating its data handling policy. The compliance officer asks which two classification labels are most appropriate for a patient's electronic protected health information (ePHI) under a typical data classification scheme aligned with HIPAA expectations. (Choose two.)
88A hospital's IT department issues a document that tells administrators the exact sequence of steps to disable a terminated clinician's account, including which systems to check and in what order. The document is mandatory and is referenced during audits. Which type of security documentation does this describe?
89A healthcare organization stores patient records and must comply with the HIPAA Security Rule. The CISO wants to document the types of safeguards that protect data through encryption, access controls, and audit logging. Which category of safeguards under the HIPAA Security Rule covers these controls?
90A financial services company must retain security event logs for a period defined by its policy and applicable regulations. The security architect is documenting how long different log sources must be kept and where. Which statement best reflects a sound log retention practice for security operations?
91A hospital must protect patient records under a regulation that specifies administrative, physical, and technical safeguards for electronic protected health information. Which U.S. regulation establishes these requirements?
92A security administrator is configuring a firewall rule set to control traffic between the corporate network and the internet. The policy states that only web browsing (HTTP and HTTPS) should be allowed outbound, and all other outbound traffic should be denied. Which type of security control is this an example of?
93A security analyst is reviewing the organization's password policy. The policy currently requires passwords to be at least 8 characters and changed every 60 days. The analyst recommends aligning with NIST SP 800-63B guidelines. Which change should the analyst recommend?
94A financial services firm must retain security event logs for seven years to satisfy regulatory requirements. The SOC manager asks which property of log data must be preserved so that logs cannot be altered or deleted after collection, even by administrators. Which property should the manager emphasize?
95A security analyst is reviewing an incident response policy that requires the team to preserve evidence for potential legal action. The analyst notices that the policy does not address how to handle evidence when a compromised system must be rebooted to restore services. What should the analyst recommend to balance evidence preservation with operational recovery?
96A security manager is developing a business continuity plan (BCP) for a critical e-commerce application. The application has a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 15 minutes. The manager must choose a backup strategy that meets these objectives. Which strategy is most appropriate?
97A security manager is preparing an incident response plan for a retail company. The plan must define how the organization will handle incidents consistently and must satisfy auditors. Which TWO elements are essential components of an incident response policy? (Choose two.)
98A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. Which TWO handling requirements are typically associated with data classified as 'Restricted'? (Choose two.)
99A security team wants to adopt a framework that provides a common language for describing cyberthreats, including tactics, techniques, and procedures observed in real intrusions. Which framework should the team use to map adversary behavior?
100A security analyst is tasked with developing a data loss prevention (DLP) strategy for the organization. The strategy must align with the CyberOps Associate curriculum and address both endpoint and network-based data exfiltration. Which two actions should the analyst include in the strategy? (Choose two.)
101An organization classifies data into Public, Internal, Confidential, and Restricted tiers. A developer needs to place a dataset containing customer payment card numbers into the correct tier and apply the required handling controls. According to common data classification practices, which tier and control combination is most appropriate?
102A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. The analyst finds that a marketing team has stored a file containing customer credit card numbers on a shared drive accessible to all employees. The analyst must recommend the appropriate classification and handling for this file. What should the analyst recommend?
103A security analyst is reviewing the organization's password policy, which currently requires a minimum of eight characters with complexity but no expiration. After a recent audit finding, management wants to align with modern best practices. Which change should the analyst recommend?
104A multinational manufacturer handles personal data of employees in several countries and wants to ensure its security program aligns with recognized international standards for establishing, implementing, maintaining, and continually improving an information security management system. Which framework should the security team adopt as the primary basis for this program?
105A financial services firm must retain security audit logs for a period specified by its regulator and be able to produce them during an examination. Which action BEST ensures the logs remain trustworthy and available for that purpose?
106A security manager is developing a business continuity plan (BCP) and needs to determine the maximum tolerable downtime (MTD) for a critical order-processing system. The system generates $10,000 in revenue per hour. If the system is down for more than 4 hours, the company will lose a key customer. What is the MTD for this system?
107A company's security policy requires that privileged accounts use multi-factor authentication for all administrative access. An auditor finds that a database administrator logs in with a username and password only, then uses a shared service account with a static password for automation. Which policy violation represents the greater risk to the organization?
108A security analyst is reviewing the organization's incident response plan and notices that the 'Lessons Learned' phase is scheduled only after major incidents. The analyst recommends that this phase be conducted after all incidents, regardless of severity. What is the primary benefit of this recommendation?
109A security manager is drafting a data classification policy and wants to ensure handling requirements are applied consistently. Which TWO elements should the policy define for each classification level? (Choose two.)
110A multinational retailer is aligning its security program with the NIST Cybersecurity Framework. The CISO wants to prioritize activities that improve the ability to detect and respond to cybersecurity events. Which Function in the NIST CSF Core is specifically described as encompassing activities to identify the occurrence of a cybersecurity event?
111A security manager is updating the organization's security awareness program after several incidents caused by employees inserting found USB drives. The manager wants a control that both reduces the likelihood of this behavior and provides a measurable metric for the awareness program. Which approach best meets both goals?
Be able to place a scenario in the correct NIST SP 800-61 phase, pick containment that preserves volatile evidence, and describe forensic integrity steps. The single most important thing: never destroy volatile data before capturing it, and document chain of custody.
The Courseiva 200-201 question bank contains 111 questions in the Security Policies and Procedures domain, covering the 15% of the exam attributed to this domain in the official Cisco blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Security Policies and Procedures domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included