Courseiva

200-201 · domain

Security Policies and Procedures

Practise Cisco CyberOps Associate 200-201 Security Policies and Procedures practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

71 questions18 easy33 medium20 hard

Focused practice

Practice Security Policies and Procedures questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Security Policies and Procedures

Security Policies and Procedures questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Security Policies and Procedures exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Security Policies and Procedures questions (71)

Click any question to see the full explanation, or start a practice session above.

1

A SOC Tier 2 analyst is investigating an alert that was escalated by Tier 1. The analyst needs to perform deeper correlation and malware analysis. Which of the following actions is most appropriate for Tier 2?

Hard
2

During an incident, a SOC Tier 1 analyst identifies a series of failed login attempts from an internal IP address. The analyst escalates the alert. What is the primary role of a Tier 2 analyst in this scenario?

Medium
3

Which SOC tier is responsible for threat hunting and advanced forensic analysis?

Easy
4

Which organization facilitates threat intelligence sharing among members in a specific sector, such as finance or healthcare?

Easy
5

During the Containment, Eradication, and Recovery phase, which TWO actions are typically performed? (Select two.)

Medium
6

During a risk assessment, a company identifies that the annualized loss expectancy (ALE) for a specific threat is $50,000. The cost to implement a mitigation control is $30,000 with an annual maintenance cost of $5,000. According to risk management principles, what is the most appropriate risk treatment option?

Hard
7

An organization is implementing an AUP that prohibits personal use of corporate resources. However, an employee uses a company laptop to access personal email, which leads to a malware infection. Which policy violation is most directly implicated?

Hard
8

A SOC Tier 3 analyst is performing threat hunting. Which activity best describes the primary focus of a Tier 3 analyst?

Hard
9

Which TWO standards/protocols are directly associated with threat intelligence sharing as defined by the CyberOps Associate curriculum?

Hard
10

An organization is implementing a threat intelligence sharing program. Which THREE elements are commonly used standards or platforms for sharing threat intelligence?

Hard
11

During a security incident involving an insider threat, which TWO roles are most likely to be directly involved in the response?

Medium
12

An organization is reviewing its risk management process and identifies a risk with a high probability and high impact. Management decides to stop the activity causing the risk. Which risk treatment option is being applied?

Medium
13

Which risk treatment option involves implementing security controls to reduce the likelihood or impact of a risk?

Easy
14

A company's legal counsel is involved in an incident response due to a data breach. What is the primary role of legal counsel during the incident?

Medium
15

Which risk treatment option involves taking actions to reduce the likelihood or impact of a risk?

Easy
16

An organization's incident response team has identified a malware infection on a critical server. They need to collect evidence for potential legal action. Which of the following is the most important step to ensure the admissibility of the evidence?

Hard
17

Which TWO roles are typically responsible for making decisions regarding business impact and external communication during an incident? (Select two.)

Easy
18

An organization is required to preserve data that may be relevant to a lawsuit. Which legal process is invoked to prevent destruction of this data?

Hard
19

During a security incident, the CISO decides to contain a compromised server by isolating it from the network. Which role is primarily responsible for making this containment decision based on business impact?

Hard
20

In the context of risk management, which THREE are valid risk treatment options?

Medium
21

After resolving a security incident, the IR team conducts a lessons learned meeting. Which of the following are typical outputs of this post-incident activity? (Choose three.)

Medium
22

An organization has implemented a new password policy requiring 12-character passwords with complexity. Which risk treatment option is this an example of?

Medium
23

A SOC Tier 1 analyst is processing alerts. Which THREE tasks are typical for a Tier 1 analyst? (Select three.)

Hard
24

A SOC analyst is investigating a potential malware outbreak. Which THREE actions should the analyst take to preserve evidence? (Select three.)

Medium
25

A security analyst is establishing a data classification policy. Which TWO categories are commonly included in a data classification policy?

Easy
26

An organization is implementing a new remote access policy. Which of the following is a key component that should be included in this policy?

Medium
27

Which role in the incident response process is primarily responsible for determining the business impact of an incident and making strategic decisions?

Medium
28

In the NIST SP 800-61 Rev 2 incident response process, which phase involves activities such as performing lessons learned and updating the incident response plan?

Easy
29

Which security policy defines acceptable use of an organization's IT resources, including internet browsing and email?

Easy
30

During the Detection and Analysis phase of incident response, a SOC Tier 1 analyst identifies a potential malware infection on a critical server. What is the FIRST action the analyst should take according to NIST SP 800-61 Rev 2?

Medium
31

A security analyst needs to share threat intelligence with other organizations in a standardized, machine-readable format. Which combination of standards should the analyst use?

Hard
32

During an incident, a forensic analyst needs to preserve evidence from a compromised hard drive. Which of the following steps is essential to maintain the chain of custody?

Hard
33

A security team is implementing a remote access policy. Which TWO controls should be included to ensure secure remote access?

Hard
34

An employee is suspected of using company resources to access inappropriate websites. Which security policy most directly addresses this behavior?

Easy
35

Which of the following are responsibilities of the legal counsel role during incident response? (Choose two.)

Medium
36

A SOC analyst at Tier 1 receives an alert for a known malware signature. After initial investigation, the analyst finds that the alert is a false positive caused by an outdated signature. What should the analyst do next?

Medium
37

A security analyst is collecting evidence from a compromised system for legal proceedings. Which TWO actions are critical to preserve the integrity of the evidence?

Medium
38

Which threat intelligence sharing standard defines a language and format for representing structured threat information, such as indicators and campaigns?

Medium
39

A financial institution is evaluating risk treatment options for a newly identified vulnerability in its online banking platform. The vulnerability has a high likelihood of exploitation but low business impact. Which risk treatment option is most appropriate?

Hard
40

Which TWO are examples of risk treatment options? (Select two.)

Easy
41

A security analyst at a SOC Tier 1 receives an alert about a potential malware infection on a user's workstation. What is the primary responsibility of the Tier 1 analyst in this scenario?

Medium
42

During the containment phase of an incident, the IR team decides to power off a compromised server to prevent further damage. However, they later realize that this action may have destroyed volatile evidence. According to best practices, what should the team have done instead?

Hard
43

An organization uses STIX and TAXII to share threat intelligence with an ISAC. What is the purpose of TAXII in this scenario?

Medium
44

A security analyst is investigating a potential data breach. They need to preserve evidence for legal proceedings. Which action should the analyst take to ensure the integrity of the data?

Medium
45

During which phase of the NIST SP 800-61 Rev 2 incident response process should an organization develop and exercise the incident response plan?

Easy
46

Which TWO are components of the NIST SP 800-61 Rev 2 Preparation phase? (Select two.)

Medium
47

A company's security policy requires that all data classified as 'Confidential' must be encrypted at rest and in transit. This requirement is part of which policy?

Medium
48

A SOC analyst is investigating a suspected data exfiltration. The analyst needs to preserve evidence from a compromised workstation. Which of the following is the CORRECT procedure to ensure evidence integrity?

Medium
49

An incident handler collects a hard drive from a compromised server. To maintain chain of custody, which information must be documented?

Medium
50

An organization is conducting a risk assessment and assigns a monetary value to potential losses. Which risk assessment method is being used?

Medium
51

A security analyst receives an alert from the SIEM indicating a large number of failed login attempts from an external IP address targeting a user account. According to the incident response process, what should be the analyst's first action?

Medium
52

In the NIST SP 800-61 Rev 2 incident response process, which phase involves documenting lessons learned and updating the incident response plan?

Easy
53

A SOC Tier 2 analyst receives an escalated alert about a potential command-and-control (C2) communication. The analyst needs to correlate network logs with threat intelligence. Which data format and transport protocol pair is specifically designed for standardized threat intelligence sharing?

Hard
54

A company is implementing threat intelligence sharing. Which THREE standards or platforms are used for this purpose? (Select three.)

Hard
55

An organization uses a qualitative risk assessment to evaluate a new vendor. Which characteristic is typical of qualitative risk assessments?

Hard
56

During which phase of the NIST SP 800-61 Rev 2 incident response process does an organization develop an incident response plan and assemble a team?

Easy
57

During the Containment, Eradication, and Recovery phase, the incident response team collects evidence from a compromised system. Which document is used to record the chain of custody?

Medium
58

A SOC Tier 1 analyst receives an alert for a potential malware infection. What is the primary responsibility of the Tier 1 analyst?

Easy
59

A SOC Tier 3 analyst is performing advanced threat analysis. Which TWO activities are typical for this tier?

Medium
60

An organization is conducting a risk assessment and wants to assign numerical values to the likelihood and impact of risks. Which type of risk assessment is being performed?

Hard
61

After containing a security incident, the incident response team eradicates the malware and restores systems from clean backups. Which phase of the NIST SP 800-61 Rev 2 process does this represent?

Medium
62

In the context of risk management, which term describes the risk that remains after implementing security controls?

Easy
63

A security analyst is triaging an alert about a user downloading a suspicious file. According to the NIST SP 800-61 Rev 2 incident response process, in which phase does initial triage occur?

Easy
64

During an incident investigation, the IR team collects evidence from a compromised server. The evidence must be admissible in court. Which documentation is essential to maintain the chain of custody?

Hard
65

An organization is developing an Acceptable Use Policy (AUP). Which of the following topics is typically covered in an AUP?

Medium
66

During a security incident, the incident handler identifies that the breach involves personally identifiable information (PII) of customers. Which role is primarily responsible for determining if legal notification requirements apply?

Medium
67

A SOC analyst is investigating a possible insider threat. Which team member should be consulted due to the nature of the incident?

Medium
68

A SOC Tier 2 analyst is investigating an alert that was escalated from Tier 1. The analyst suspects the malware is using a new variant of ransomware. What is the most appropriate next step for the Tier 2 analyst?

Medium
69

After a security incident, the IR team holds a lessons learned meeting. Which THREE activities are part of the Post-Incident Activity phase?

Medium
70

Which of the following is the CORRECT order of the NIST SP 800-61 Rev 2 incident response lifecycle phases?

Easy
71

During which phase of the NIST SP 800-61 Rev 2 incident response process would the incident response team conduct initial triage and determine whether an event qualifies as an incident?

Easy

Frequently asked questions

What does the Security Policies and Procedures domain cover on the 200-201 exam?
Security Policies and Procedures questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 71 Security Policies and Procedures questions in the 200-201 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Security Policies and Procedures questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cisco-cyberops-associate CISCO-CYBEROPS-ASSOCIATE cbrops policies procedures Practice Questions