200-201 · domain
Security Policies and Procedures
Practise Cisco CyberOps Associate 200-201 Security Policies and Procedures practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Security Policies and Procedures questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Security Policies and Procedures
Security Policies and Procedures questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Security Policies and Procedures exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Security Policies and Procedures questions (71)
Click any question to see the full explanation, or start a practice session above.
A SOC Tier 2 analyst is investigating an alert that was escalated by Tier 1. The analyst needs to perform deeper correlation and malware analysis. Which of the following actions is most appropriate for Tier 2?
Hard2During an incident, a SOC Tier 1 analyst identifies a series of failed login attempts from an internal IP address. The analyst escalates the alert. What is the primary role of a Tier 2 analyst in this scenario?
Medium3Which SOC tier is responsible for threat hunting and advanced forensic analysis?
Easy4Which organization facilitates threat intelligence sharing among members in a specific sector, such as finance or healthcare?
Easy5During the Containment, Eradication, and Recovery phase, which TWO actions are typically performed? (Select two.)
Medium6During a risk assessment, a company identifies that the annualized loss expectancy (ALE) for a specific threat is $50,000. The cost to implement a mitigation control is $30,000 with an annual maintenance cost of $5,000. According to risk management principles, what is the most appropriate risk treatment option?
Hard7An organization is implementing an AUP that prohibits personal use of corporate resources. However, an employee uses a company laptop to access personal email, which leads to a malware infection. Which policy violation is most directly implicated?
Hard8A SOC Tier 3 analyst is performing threat hunting. Which activity best describes the primary focus of a Tier 3 analyst?
Hard9Which TWO standards/protocols are directly associated with threat intelligence sharing as defined by the CyberOps Associate curriculum?
Hard10An organization is implementing a threat intelligence sharing program. Which THREE elements are commonly used standards or platforms for sharing threat intelligence?
Hard11During a security incident involving an insider threat, which TWO roles are most likely to be directly involved in the response?
Medium12An organization is reviewing its risk management process and identifies a risk with a high probability and high impact. Management decides to stop the activity causing the risk. Which risk treatment option is being applied?
Medium13Which risk treatment option involves implementing security controls to reduce the likelihood or impact of a risk?
Easy14A company's legal counsel is involved in an incident response due to a data breach. What is the primary role of legal counsel during the incident?
Medium15Which risk treatment option involves taking actions to reduce the likelihood or impact of a risk?
Easy16An organization's incident response team has identified a malware infection on a critical server. They need to collect evidence for potential legal action. Which of the following is the most important step to ensure the admissibility of the evidence?
Hard17Which TWO roles are typically responsible for making decisions regarding business impact and external communication during an incident? (Select two.)
Easy18An organization is required to preserve data that may be relevant to a lawsuit. Which legal process is invoked to prevent destruction of this data?
Hard19During a security incident, the CISO decides to contain a compromised server by isolating it from the network. Which role is primarily responsible for making this containment decision based on business impact?
Hard20In the context of risk management, which THREE are valid risk treatment options?
Medium21After resolving a security incident, the IR team conducts a lessons learned meeting. Which of the following are typical outputs of this post-incident activity? (Choose three.)
Medium22An organization has implemented a new password policy requiring 12-character passwords with complexity. Which risk treatment option is this an example of?
Medium23A SOC Tier 1 analyst is processing alerts. Which THREE tasks are typical for a Tier 1 analyst? (Select three.)
Hard24A SOC analyst is investigating a potential malware outbreak. Which THREE actions should the analyst take to preserve evidence? (Select three.)
Medium25A security analyst is establishing a data classification policy. Which TWO categories are commonly included in a data classification policy?
Easy26An organization is implementing a new remote access policy. Which of the following is a key component that should be included in this policy?
Medium27Which role in the incident response process is primarily responsible for determining the business impact of an incident and making strategic decisions?
Medium28In the NIST SP 800-61 Rev 2 incident response process, which phase involves activities such as performing lessons learned and updating the incident response plan?
Easy29Which security policy defines acceptable use of an organization's IT resources, including internet browsing and email?
Easy30During the Detection and Analysis phase of incident response, a SOC Tier 1 analyst identifies a potential malware infection on a critical server. What is the FIRST action the analyst should take according to NIST SP 800-61 Rev 2?
Medium31A security analyst needs to share threat intelligence with other organizations in a standardized, machine-readable format. Which combination of standards should the analyst use?
Hard32During an incident, a forensic analyst needs to preserve evidence from a compromised hard drive. Which of the following steps is essential to maintain the chain of custody?
Hard33A security team is implementing a remote access policy. Which TWO controls should be included to ensure secure remote access?
Hard34An employee is suspected of using company resources to access inappropriate websites. Which security policy most directly addresses this behavior?
Easy35Which of the following are responsibilities of the legal counsel role during incident response? (Choose two.)
Medium36A SOC analyst at Tier 1 receives an alert for a known malware signature. After initial investigation, the analyst finds that the alert is a false positive caused by an outdated signature. What should the analyst do next?
Medium37A security analyst is collecting evidence from a compromised system for legal proceedings. Which TWO actions are critical to preserve the integrity of the evidence?
Medium38Which threat intelligence sharing standard defines a language and format for representing structured threat information, such as indicators and campaigns?
Medium39A financial institution is evaluating risk treatment options for a newly identified vulnerability in its online banking platform. The vulnerability has a high likelihood of exploitation but low business impact. Which risk treatment option is most appropriate?
Hard40Which TWO are examples of risk treatment options? (Select two.)
Easy41A security analyst at a SOC Tier 1 receives an alert about a potential malware infection on a user's workstation. What is the primary responsibility of the Tier 1 analyst in this scenario?
Medium42During the containment phase of an incident, the IR team decides to power off a compromised server to prevent further damage. However, they later realize that this action may have destroyed volatile evidence. According to best practices, what should the team have done instead?
Hard43An organization uses STIX and TAXII to share threat intelligence with an ISAC. What is the purpose of TAXII in this scenario?
Medium44A security analyst is investigating a potential data breach. They need to preserve evidence for legal proceedings. Which action should the analyst take to ensure the integrity of the data?
Medium45During which phase of the NIST SP 800-61 Rev 2 incident response process should an organization develop and exercise the incident response plan?
Easy46Which TWO are components of the NIST SP 800-61 Rev 2 Preparation phase? (Select two.)
Medium47A company's security policy requires that all data classified as 'Confidential' must be encrypted at rest and in transit. This requirement is part of which policy?
Medium48A SOC analyst is investigating a suspected data exfiltration. The analyst needs to preserve evidence from a compromised workstation. Which of the following is the CORRECT procedure to ensure evidence integrity?
Medium49An incident handler collects a hard drive from a compromised server. To maintain chain of custody, which information must be documented?
Medium50An organization is conducting a risk assessment and assigns a monetary value to potential losses. Which risk assessment method is being used?
Medium51A security analyst receives an alert from the SIEM indicating a large number of failed login attempts from an external IP address targeting a user account. According to the incident response process, what should be the analyst's first action?
Medium52In the NIST SP 800-61 Rev 2 incident response process, which phase involves documenting lessons learned and updating the incident response plan?
Easy53A SOC Tier 2 analyst receives an escalated alert about a potential command-and-control (C2) communication. The analyst needs to correlate network logs with threat intelligence. Which data format and transport protocol pair is specifically designed for standardized threat intelligence sharing?
Hard54A company is implementing threat intelligence sharing. Which THREE standards or platforms are used for this purpose? (Select three.)
Hard55An organization uses a qualitative risk assessment to evaluate a new vendor. Which characteristic is typical of qualitative risk assessments?
Hard56During which phase of the NIST SP 800-61 Rev 2 incident response process does an organization develop an incident response plan and assemble a team?
Easy57During the Containment, Eradication, and Recovery phase, the incident response team collects evidence from a compromised system. Which document is used to record the chain of custody?
Medium58A SOC Tier 1 analyst receives an alert for a potential malware infection. What is the primary responsibility of the Tier 1 analyst?
Easy59A SOC Tier 3 analyst is performing advanced threat analysis. Which TWO activities are typical for this tier?
Medium60An organization is conducting a risk assessment and wants to assign numerical values to the likelihood and impact of risks. Which type of risk assessment is being performed?
Hard61After containing a security incident, the incident response team eradicates the malware and restores systems from clean backups. Which phase of the NIST SP 800-61 Rev 2 process does this represent?
Medium62In the context of risk management, which term describes the risk that remains after implementing security controls?
Easy63A security analyst is triaging an alert about a user downloading a suspicious file. According to the NIST SP 800-61 Rev 2 incident response process, in which phase does initial triage occur?
Easy64During an incident investigation, the IR team collects evidence from a compromised server. The evidence must be admissible in court. Which documentation is essential to maintain the chain of custody?
Hard65An organization is developing an Acceptable Use Policy (AUP). Which of the following topics is typically covered in an AUP?
Medium66During a security incident, the incident handler identifies that the breach involves personally identifiable information (PII) of customers. Which role is primarily responsible for determining if legal notification requirements apply?
Medium67A SOC analyst is investigating a possible insider threat. Which team member should be consulted due to the nature of the incident?
Medium68A SOC Tier 2 analyst is investigating an alert that was escalated from Tier 1. The analyst suspects the malware is using a new variant of ransomware. What is the most appropriate next step for the Tier 2 analyst?
Medium69After a security incident, the IR team holds a lessons learned meeting. Which THREE activities are part of the Post-Incident Activity phase?
Medium70Which of the following is the CORRECT order of the NIST SP 800-61 Rev 2 incident response lifecycle phases?
Easy71During which phase of the NIST SP 800-61 Rev 2 incident response process would the incident response team conduct initial triage and determine whether an event qualifies as an incident?
EasyOther domains
All 200-201 exam domains
Frequently asked questions
- What does the Security Policies and Procedures domain cover on the 200-201 exam?
- Security Policies and Procedures questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 71 Security Policies and Procedures questions in the 200-201 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Security Policies and Procedures questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.