Courseiva

CCNA Security Policies and Procedures Questions

75 of 111 questions · Page 1/2 · Security Policies and Procedures · Answers revealed

1
MCQhard

A multinational manufacturer handles personal data of employees in several countries and wants to ensure its security program aligns with recognized international standards for establishing, implementing, maintaining, and continually improving an information security management system. Which framework should the security team adopt as the primary basis for this program?

A.CIS Critical Security Controls
B.ISO/IEC 27001
C.PCI DSS
D.NIST Cybersecurity Framework
AnswerB

ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system, which is exactly what the scenario describes. It is internationally recognized and applicable across jurisdictions, making it suitable for a multinational manufacturer. The standard's management-system approach also supports certification, which provides external validation of the program.

Why this answer

ISO/IEC 27001 is the internationally recognized standard that specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system. That scope matches the manufacturer's goal of a globally aligned, certifiable security program. The NIST Cybersecurity Framework, CIS Controls, and PCI DSS serve different purposes: voluntary taxonomy, technical safeguards, and payment card requirements, respectively.

Exam trap

The trap here is selecting a widely known security framework based on familiarity, without checking whether it defines a certifiable management system, which is the specific requirement described.

2
MCQhard

A SOC Tier 2 analyst is investigating an alert that was escalated by Tier 1. The analyst needs to perform deeper correlation and malware analysis. Which of the following actions is most appropriate for Tier 2?

A.Analyze the malware sample in a sandbox and correlate with other indicators.
B.Conduct threat hunting to proactively search for threats.
C.Develop new detection rules for the SIEM.
D.Perform initial triage and basic investigation.
AnswerA

Sandbox detonation executes the sample in an isolated environment, revealing runtime behaviour such as command-and-control callbacks, dropped files and registry persistence that static inspection misses. Correlating those artefacts with other indicators satisfies the Tier 2 requirement for deeper malware analysis and cross-event correlation, exceeding Tier 1 triage scope.

Why this answer

Tier 2 analysts are responsible for deeper investigation, including malware analysis and correlating indicators across multiple data sources. Analyzing a malware sample in a sandbox allows safe execution and observation of behavior, while correlation with other indicators (e.g., IOCs from other alerts) helps determine scope and impact. This aligns with the escalation from Tier 1, which typically handles initial triage.

Options B and C are more advanced or proactive tasks often handled by Tier 3 or threat hunting teams, and D is a Tier 1 responsibility.

Exam trap

The trap here is confusing the responsibilities of different SOC tiers, particularly assuming that proactive tasks like threat hunting or detection engineering are part of Tier 2's reactive investigation role.

How to eliminate wrong answers

Option B is wrong because threat hunting is a proactive activity typically performed by Tier 3 or dedicated threat hunting teams, not a reactive escalation task for Tier 2. Option C is wrong because developing new detection rules is a engineering or Tier 3 responsibility, not part of the immediate investigation of an escalated alert. Option D is wrong because initial triage and basic investigation are Tier 1 duties, and the scenario explicitly states the alert was escalated to Tier 2, meaning Tier 1 has already completed those steps.

3
MCQmedium

During an incident, a SOC Tier 1 analyst identifies a series of failed login attempts from an internal IP address. The analyst escalates the alert. What is the primary role of a Tier 2 analyst in this scenario?

A.Monitor alerts and perform initial triage
B.Make decisions on business impact and notification
C.Conduct threat hunting and advanced forensics
D.Perform deeper investigation and correlate events
AnswerD

Tier 2 analysts handle escalated alerts requiring deeper forensic analysis, correlating the failed logins with other telemetry to determine scope and intent. This satisfies the scenario's need to validate whether the internal IP indicates compromise rather than routine user error.

Why this answer

Tier 2 analysts take escalated alerts from Tier 1 and perform deeper investigation, correlating events across multiple log sources, endpoints, and network telemetry to determine scope and root cause. In this scenario, the failed login attempts from an internal IP require correlation with authentication logs, endpoint activity, and threat intelligence — exactly the Tier 2 function.

Exam trap

200-201 often tests role boundaries in the SOC — the trap is selecting 'threat hunting' or 'business impact decisions' for Tier 2 when those belong to Tier 3 or management, while the correct answer is the narrower 'deeper investigation and correlation.'

How to eliminate wrong answers

Option A is wrong because monitoring alerts and initial triage is the Tier 1 responsibility, not Tier 2. Option B is wrong because decisions on business impact and stakeholder notification are typically made by incident response management or Tier 3/leadership, not the Tier 2 analyst's primary role. Option C is wrong because proactive threat hunting and advanced forensics are generally Tier 3 or dedicated threat-hunting team activities, beyond the reactive escalation scope of Tier 2.

4
MCQeasy

Which SOC tier is responsible for threat hunting and advanced forensic analysis?

A.Tier 1
B.Tier 3
C.All tiers equally
D.Tier 2
AnswerB

Tier 3 analysts handle proactive threat hunting and deep forensic investigation, the highest analytical escalation level. Tier 1 performs triage and monitoring, Tier 2 handles incident response escalation; advanced forensics and hunting sit with Tier 3, matching the responsibilities named in the question.

Why this answer

Tier 3 SOC analysts are the most senior and are responsible for advanced threat hunting, malware reverse engineering, and deep forensic analysis. Tier 1 handles initial triage and alert monitoring, while Tier 2 performs deeper investigation and incident response. Threat hunting and forensics are explicitly Tier 3 responsibilities in the standard SOC tier model.

Exam trap

The trap here is confusing Tier 2's incident response duties with Tier 3's proactive threat hunting and forensic analysis — candidates often pick Tier 2 because it sounds 'advanced' enough.

How to eliminate wrong answers

Option A is wrong because Tier 1 analysts perform initial alert triage, ticket creation, and basic escalation — they do not conduct threat hunting or forensic analysis. Option C is wrong because responsibilities are not shared equally across tiers; the tiered model exists precisely to distribute escalating skill levels and duties. Option D is wrong because Tier 2 handles incident investigation and response but stops short of the advanced hunting and forensic deep dives reserved for Tier 3.

5
MCQeasy

Which organization facilitates threat intelligence sharing among members in a specific sector, such as finance or healthcare?

A.MISP
B.ISAC
C.STIX
D.TAXII
AnswerB

ISACs are sector-specific non-profit organisations that collect, analyse and share threat intelligence among members within industries such as finance or healthcare. They satisfy the stem's requirement for a sector-focused sharing body, unlike cross-sector or government-led alternatives.

Why this answer

ISACs (Information Sharing and Analysis Centers) are sector-specific organizations that facilitate threat intelligence sharing among members in industries such as finance (FS-ISAC), healthcare (H-ISAC), and aviation. They provide a trusted forum for members to exchange threat data, best practices, and incident information relevant to their sector.

Exam trap

200-201 often tests the confusion between threat intelligence sharing organizations (ISACs) and the standards/platforms used to share intelligence (STIX, TAXII, MISP), tricking candidates into selecting a technology instead of an organization.

How to eliminate wrong answers

Option A is wrong because MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for storing and sharing indicators, not an organization that facilitates sector-specific sharing. Option C is wrong because STIX (Structured Threat Information Expression) is a standardized language for representing threat intelligence, not an organization. Option D is wrong because TAXII (Trusted Automated Exchange of Intelligence Information) is a protocol for transporting threat intelligence over HTTPS, not an organization.

6
MCQmedium

A security manager is developing a business continuity plan (BCP) for a critical e-commerce application. The application has a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 15 minutes. The manager must choose a backup strategy that meets these objectives. Which strategy is most appropriate?

A.Weekly incremental backups to a warm site with manual failover.
B.Continuous data replication to a hot site with automated failover.
C.Daily differential backups to a cold site with tape restoration.
D.Nightly full backups stored offsite with manual restore.
AnswerB

Continuous replication keeps the recovery site synchronized with minimal data loss, meeting the 15-minute RPO. A hot site with automated failover can bring the application online within the 4-hour RTO. This strategy provides the highest availability and is suitable for critical e-commerce. It aligns with both objectives by minimizing downtime and data loss.

Why this answer

The RTO of 4 hours requires recovery within that time, and the RPO of 15 minutes requires minimal data loss. Continuous replication to a hot site with automated failover can achieve both by keeping data synchronized and enabling rapid switchover. Other strategies like nightly, weekly, or daily backups introduce too much data loss and longer recovery times, failing to meet the objectives.

Exam trap

The trap here is selecting a backup strategy based on cost or simplicity without checking whether it satisfies both the RTO and RPO, especially the 15-minute RPO which requires near-real-time replication.

7
MCQhard

A security team wants to adopt a framework that provides a common language for describing cyberthreats, including tactics, techniques, and procedures observed in real intrusions. Which framework should the team use to map adversary behavior?

A.ISO/IEC 27001
B.MITRE ATT&CK
C.NIST Cybersecurity Framework
D.CVSS
AnswerB

MITRE ATT&CK is a curated knowledge base of adversary tactics and techniques derived from real-world observations. It gives defenders a common vocabulary such as initial access, persistence, and credential dumping, letting teams map detections, prioritize coverage, and compare intrusions. The scenario explicitly asks for a framework that describes tactics, techniques, and procedures observed in real intrusions, which is exactly what ATT&CK provides.

Why this answer

MITRE ATT&CK is the framework that catalogs real-world adversary tactics and techniques, giving defenders a shared vocabulary for describing intrusions. Teams use it to map detections to techniques, identify coverage gaps, and communicate findings consistently. Governance standards and vulnerability scoring systems serve different purposes and do not describe adversary behavior.

Exam trap

The trap here is selecting a well-known security framework by reputation alone, when only one framework actually catalogs adversary tactics and techniques.

8
Multi-Selecthard

A security analyst is tasked with developing a data loss prevention (DLP) strategy for the organization. The strategy must align with the CyberOps Associate curriculum and address both endpoint and network-based data exfiltration. Which two actions should the analyst include in the strategy? (Choose two.)

Select 2 answers
A.Deploy network DLP solutions to inspect outbound traffic for sensitive data patterns and block unauthorized transfers.
B.Implement role-based access control (RBAC) to limit access to sensitive data.
C.Implement endpoint DLP agents to monitor and control data transfers to removable media and cloud storage.
D.Configure full-disk encryption on all endpoints to prevent data loss if a device is stolen.
E.Establish a security awareness program to educate employees about data handling policies.
AnswersA, C

Network DLP monitors data in transit across the network perimeter. It can detect and block sensitive information leaving the organization via email, web uploads, or other protocols. This complements endpoint DLP by providing a centralized enforcement point and covering devices that may not have agents installed. Together, they form a layered defense against data exfiltration, as recommended by security best practices.

Why this answer

The two actions to include are endpoint DLP and network DLP. Endpoint DLP controls data transfers at the device level, such as to USB drives or cloud services, while network DLP inspects outbound traffic for sensitive data. Together, they provide comprehensive coverage for data exfiltration across both endpoints and the network.

These technical controls directly address the requirement to monitor and prevent unauthorized data transfers, aligning with the CyberOps Associate curriculum's focus on data protection.

Exam trap

The trap here is confusing data-at-rest protection like encryption with data-in-motion controls, which are the core of DLP.

9
MCQhard

During a risk assessment, a company identifies that the annualized loss expectancy (ALE) for a specific threat is $50,000. The cost to implement a mitigation control is $30,000 with an annual maintenance cost of $5,000. According to risk management principles, what is the most appropriate risk treatment option?

A.Accept the risk because the mitigation cost is higher than the ALE
B.Avoid the risk by discontinuing the activity
C.Transfer the risk by purchasing cyber insurance
D.Mitigate the risk by implementing the control
AnswerD

The control's total annual cost is $35,000, which is lower than the $50,000 ALE, so mitigation yields a positive return and reduces expected loss. This satisfies the risk management principle of selecting treatment where control cost is less than the annualised loss expectancy.

Why this answer

If the cost of mitigation ($30,000 + $5,000 = $35,000) is less than the ALE ($50,000), it is cost-effective to mitigate the risk.

10
MCQhard

An organization is implementing an AUP that prohibits personal use of corporate resources. However, an employee uses a company laptop to access personal email, which leads to a malware infection. Which policy violation is most directly implicated?

A.Remote access policy
B.Information security policy
C.Password policy
D.Acceptable Use Policy (AUP)
AnswerD

The Acceptable Use Policy defines permitted and prohibited use of corporate resources, including personal email access on a company laptop. The employee's action breaches that policy directly, and the resulting malware infection stems from this specific violation.

Why this answer

The Acceptable Use Policy (AUP) defines acceptable behavior regarding the use of company resources. Personal use that violates the AUP is a direct policy breach.

11
MCQhard

A SOC Tier 3 analyst is performing threat hunting. Which activity best describes the primary focus of a Tier 3 analyst?

A.Monitoring incoming alerts for potential incidents
B.Correlating alerts from multiple sources
C.Proactively searching for advanced threats
D.Creating user accounts and permissions
AnswerC

Tier 3 analysts perform proactive threat hunting, using advanced analytics and intelligence to find threats evading existing detection. This satisfies the stem's focus on hunting, distinguishing it from Tier 1 triage and Tier 2 escalation duties.

Why this answer

A Tier 3 analyst is the most senior level in a SOC, responsible for proactive threat hunting—actively searching for advanced threats that evade existing detection tools. Unlike Tier 1 and Tier 2, which focus on alert triage and correlation, Tier 3 uses hypothesis-driven investigations, threat intelligence, and advanced analytics to uncover stealthy adversaries. This aligns with the primary focus of a Tier 3 analyst as defined in the 200-201 exam objectives.

Exam trap

The trap here is confusing the responsibilities of different SOC tiers, especially assuming that Tier 3 primarily handles alert correlation or monitoring, when in fact those are Tier 1 and Tier 2 duties.

How to eliminate wrong answers

Option A is wrong because monitoring incoming alerts is a Tier 1 responsibility, not Tier 3. Option B is wrong because correlating alerts from multiple sources is typically a Tier 2 task, not the primary focus of Tier 3. Option D is wrong because creating user accounts and permissions is an administrative or IAM function, unrelated to SOC analyst roles.

12
MCQeasy

A new security analyst is reviewing the organization's data classification policy and notices that data labeled 'Restricted' must be encrypted at rest and in transit, while data labeled 'Internal' has no encryption requirement. The analyst asks why the policy distinguishes between these levels. What is the primary purpose of a data classification policy?

A.To provide a legal shield that eliminates liability if data is breached
B.To specify which employees are allowed to access the internet from corporate devices
C.To define handling requirements based on the sensitivity and value of the data
D.To ensure all data receives the same level of protection regardless of sensitivity
AnswerC

This is correct because data classification assigns labels such as 'Restricted' or 'Internal' based on sensitivity, and each label maps to specific handling, encryption, and access requirements. The policy in the scenario applies stronger controls to more sensitive data, which is the core function of classification. It enables risk-based protection aligned with business and compliance needs.

Why this answer

A data classification policy categorizes information by sensitivity and value so that appropriate controls, such as encryption for 'Restricted' data, can be applied consistently. It supports risk-based decision-making, regulatory compliance, and clear handling procedures. The distinction between 'Restricted' and 'Internal' in the scenario exists precisely to ensure stronger protections are applied where the impact of disclosure is greatest.

Exam trap

The trap here is assuming that a data classification policy is about access control lists or legal immunity rather than about mapping data sensitivity to handling requirements.

13
Multi-Selecthard

An organization is implementing a threat intelligence sharing program. Which THREE elements are commonly used standards or platforms for sharing threat intelligence?

Select 3 answers
A.MISP
B.ISAC
C.TAXII
D.STIX
E.OpenIOC
AnswersA, C, D

MISP is an open-source threat intelligence sharing platform where organisations exchange indicators, events and correlated attributes. It satisfies the sharing requirement by providing a common repository and community, complementing the STIX format and TAXII transport protocol named elsewhere.

Why this answer

MISP (Malware Information Sharing Platform) is correct because it is a widely used open-source threat intelligence platform that enables organizations to store, correlate, and share indicators of compromise and threat data with trusted partners. TAXII (Trusted Automated Exchange of Intelligence Information) is correct because it is the OASIS-defined application-layer protocol specifically designed to transport cyber threat intelligence over HTTPS between parties. STIX (Structured Threat Information Expression) is correct because it is the standardized language/schema used to represent cyber threat intelligence in a structured, machine-readable form, and it is commonly paired with TAXII for exchange.

ISACs (Information Sharing and Analysis Centers) are sector-specific sharing organizations rather than a technical standard or platform, and OpenIOC is a proprietary Mandiant indicator format that never became a broadly adopted sharing standard, so neither belongs here.

14
MCQmedium

An organization is reviewing its risk management process and identifies a risk with a high probability and high impact. Management decides to stop the activity causing the risk. Which risk treatment option is being applied?

A.Risk mitigation
B.Risk acceptance
C.Risk avoidance
D.Risk transfer
AnswerC

Risk avoidance eliminates the risk by discontinuing the activity entirely, which matches management stopping the process outright. Unlike mitigation, which reduces likelihood or impact, or transfer, which shifts financial consequence, avoidance removes the exposure at source.

Why this answer

Risk avoidance is the treatment option where the organization eliminates the risk entirely by discontinuing the activity that creates it. Since management decided to stop the activity causing the high-probability, high-impact risk, this is avoidance. It is the only option that removes the risk rather than reducing, accepting, or transferring it.

Exam trap

200-201 often tests the distinction between avoidance and mitigation — candidates pick mitigation because 'stopping the activity' sounds like a control, but avoidance specifically means eliminating the activity, not reducing its risk.

How to eliminate wrong answers

Option A is wrong because risk mitigation reduces likelihood or impact through controls but does not stop the activity — the risk still exists in reduced form. Option B is wrong because risk acceptance means acknowledging the risk and taking no action, which is the opposite of stopping the activity. Option D is wrong because risk transfer shifts the risk to a third party (e.g., insurance) while the activity continues, which does not match management's decision to stop the activity.

15
MCQeasy

Which risk treatment option involves implementing security controls to reduce the likelihood or impact of a risk?

A.Avoid
B.Mitigate
C.Transfer
D.Accept
AnswerB

Mitigate reduces risk through controls.

Why this answer

Mitigate is the risk treatment option that involves implementing security controls to reduce the likelihood or impact of a risk. This can include technical controls (e.g., firewalls, encryption), administrative controls (e.g., policies, training), or physical controls (e.g., locks, guards). Mitigation aims to bring the risk down to an acceptable level rather than eliminating it entirely.

Exam trap

200-201 often tests the confusion between Mitigate and Transfer, since both involve taking action; candidates must remember that Mitigate reduces risk through controls, while Transfer shifts the financial or operational burden to another party.

How to eliminate wrong answers

Option A is wrong because Avoid involves eliminating the risk by not performing the activity that introduces it (e.g., discontinuing a service). Option C is wrong because Transfer shifts the risk to a third party, such as through insurance or outsourcing, without reducing it. Option D is wrong because Accept means acknowledging the risk and taking no action, often because the cost of mitigation exceeds the potential loss.

16
MCQmedium

A company's legal counsel is involved in an incident response due to a data breach. What is the primary role of legal counsel during the incident?

A.Make decisions about business impact
B.Communicate with the public
C.Conduct forensic analysis of affected systems
D.Advise on data breach notification requirements
AnswerD

Legal counsel interprets breach notification statutes and contractual obligations, advising when and to whom affected parties and regulators must be told. This satisfies the stem's data breach scenario, since notification deadlines and wording carry legal weight distinct from technical containment or forensic analysis.

Why this answer

Legal counsel ensures compliance with data breach notification laws.

17
MCQeasy

Which risk treatment option involves taking actions to reduce the likelihood or impact of a risk?

A.Mitigate
B.Accept
C.Transfer
D.Avoid
AnswerA

Mitigation reduces risk through controls.

Why this answer

Mitigation (also called risk reduction) is the risk treatment option where an organization takes deliberate actions to lower either the likelihood that a risk materializes or the severity of its impact if it does. Examples include applying patches, adding firewalls, or implementing MFA. It is the only option that actively modifies the risk itself rather than shifting, eliminating, or tolerating it.

Exam trap

The trap here is confusing 'transfer' with 'mitigate' — candidates often assume buying insurance reduces risk, but transfer only shifts financial liability, not the likelihood or impact of the event itself.

How to eliminate wrong answers

Option B is wrong because acceptance means acknowledging the risk and choosing to take no action (or only monitoring it), which does not reduce likelihood or impact. Option C is wrong because transfer shifts the financial or operational burden to a third party (e.g., cyber insurance or outsourcing) without reducing the underlying likelihood or impact. Option D is wrong because avoidance eliminates the risk entirely by discontinuing the activity that creates it, rather than reducing it.

18
MCQhard

An organization's incident response team has identified a malware infection on a critical server. They need to collect evidence for potential legal action. Which of the following is the most important step to ensure the admissibility of the evidence?

A.Contacting legal counsel before proceeding
B.Documenting the chain of custody for all evidence
C.Creating a forensic image of the affected hard drive
D.Isolating the server from the network
AnswerB

Chain-of-custody documentation records every transfer, handler and storage condition of the seized media, proving the evidence was not altered or tampered with. Without this unbroken audit trail, courts may rule the malware artefacts inadmissible, regardless of how technically sound the forensic acquisition itself was.

Why this answer

Maintaining a proper chain of custody documents who handled the evidence and ensures it has not been tampered with, which is critical for legal admissibility.

19
MCQmedium

A multinational retailer is aligning its security program with the NIST Cybersecurity Framework. The CISO wants to prioritize activities that improve the ability to detect and respond to cybersecurity events. Which Function in the NIST CSF Core is specifically described as encompassing activities to identify the occurrence of a cybersecurity event?

A.Protect
B.Identify
C.Detect
D.Respond
AnswerC

Detect is the NIST CSF Function that includes activities to identify the occurrence of a cybersecurity event, covering anomalies and events, continuous security monitoring, and detection processes. For the retailer's goal of improving event discovery, Detect is the correct focus because it addresses monitoring, analysis, and timely awareness. Investments in this Function, such as SIEM tuning and endpoint detection, directly strengthen the ability to notice malicious activity quickly.

Why this answer

The NIST CSF Core defines Detect as the Function containing activities to identify the occurrence of a cybersecurity event, including continuous monitoring and detection processes. Identify, Protect, and Respond address asset understanding, safeguards, and post-detection actions respectively. For a retailer seeking faster awareness of incidents, strengthening the Detect Function is the direct match.

Exam trap

The trap here is conflating Identify, which is about understanding assets and risk before events, with Detect, which is about recognizing that an event is happening.

20
Multi-Selecthard

A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. Which TWO handling requirements are typically associated with data classified as 'Restricted'? (Choose two.)

Select 2 answers
A.Data can be declassified to Public after 30 days automatically.
B.Access is limited to a need-to-know basis with strict approval workflows.
C.Data must be stored only on removable media for physical security.
D.Data can be shared freely within the organization without additional controls.
E.Data must be encrypted both at rest and in transit.
AnswersB, E

Restricted data is usually subject to strict access controls, where only individuals with a specific need-to-know and proper approvals can access it. This minimizes the risk of insider threats and accidental exposure. Need-to-know access is a hallmark of handling requirements for the most sensitive data classifications.

Why this answer

Restricted data, as the highest classification, requires strong protections such as encryption at rest and in transit, and access limited to a need-to-know basis with strict approvals. These controls reduce the risk of unauthorized disclosure. Free sharing, mandatory removable media storage, and automatic declassification are not typical requirements and would weaken security.

Exam trap

The trap here is assuming that all sensitive data can be handled the same way, when in fact Restricted data demands the strictest controls, including encryption and need-to-know access.

21
MCQhard

An organization is required to preserve data that may be relevant to a lawsuit. Which legal process is invoked to prevent destruction of this data?

A.E-discovery
B.Legal hold
C.Chain of custody
D.Data retention policy
AnswerB

Legal hold suspends normal retention and deletion schedules, preserving data that may be relevant to anticipated or active litigation. It satisfies the stem's requirement to prevent destruction of lawsuit-relevant data, unlike spoliation, which describes the improper loss itself. Microsoft Entra ID and Microsoft Purview apply holds to mailboxes, sites and identities.

Why this answer

A legal hold is the process invoked to preserve data that may be relevant to litigation, preventing its destruction or modification. It overrides normal retention and deletion policies, ensuring electronically stored information (ESI) is retained until the hold is released. In Microsoft 365, this is implemented via Litigation Hold or eDiscovery holds on mailboxes and sites.

Exam trap

The trap is confusing e-discovery (the overall process) with legal hold (the specific preservation action) — candidates pick e-discovery because it sounds like the legal process, but the question asks what prevents destruction.

How to eliminate wrong answers

Option A is wrong because e-discovery is the broader process of identifying, collecting, and producing ESI for litigation; it may include a hold, but the hold itself is the preservation mechanism. Option C is wrong because chain of custody documents the handling and transfer of evidence to ensure integrity; it does not prevent data destruction. Option D is wrong because a data retention policy defines how long data is kept and when it is deleted; it does not specifically preserve data for litigation and may even cause deletion.

22
MCQeasy

A healthcare organization is developing an incident response plan. The security manager wants to ensure that the plan includes a phase where the team practices and tests their response capabilities before an actual incident occurs. According to the NIST incident response lifecycle, which phase involves preparing and preventing incidents through activities like training and exercises?

A.Post-Incident Activity
B.Containment, Eradication, and Recovery
C.Detection and Analysis
D.Preparation
AnswerD

Preparation is the first phase of the NIST incident response lifecycle. It encompasses establishing an incident response capability, developing plans, training personnel, and conducting exercises. In this scenario, the security manager wants to ensure the team practices and tests capabilities, which is exactly what happens during Preparation. This phase sets the foundation for effective incident handling.

Why this answer

According to the NIST incident response lifecycle, Preparation is the phase dedicated to establishing and maintaining incident response capabilities, including training, exercises, and plan development. The other phases are reactive and occur during or after an incident. Therefore, the security manager should focus on Preparation to ensure the team is ready before an incident happens.

Exam trap

The trap here is assuming that Post-Incident Activity includes training, but that phase is about reviewing and learning from the incident, not practicing beforehand.

23
MCQeasy

A hospital must protect patient records under a regulation that specifies administrative, physical, and technical safeguards for electronic protected health information. Which U.S. regulation establishes these requirements?

A.SOX
B.HIPAA Security Rule
C.GDPR
D.PCI DSS
AnswerB

The HIPAA Security Rule sets national standards for protecting electronic protected health information and is organized precisely around administrative, physical, and technical safeguards. It applies to covered entities such as hospitals and to their business associates. The rule requires risk analysis, access controls, audit controls, integrity controls, and transmission security, making it the direct match for the scenario's described obligations.

Why this answer

The HIPAA Security Rule is the U.S. regulation that requires covered entities to implement administrative, physical, and technical safeguards for electronic protected health information. Its three safeguard categories map directly to the scenario, and compliance is enforced through risk analysis and documented policies rather than a prescriptive control checklist.

Exam trap

The trap here is confusing broadly similar privacy laws, when only one regulation is built around administrative, physical, and technical safeguards for health data.

24
MCQhard

During a security incident, the CISO decides to contain a compromised server by isolating it from the network. Which role is primarily responsible for making this containment decision based on business impact?

A.CISO
B.Incident handler
C.Legal counsel
D.PR representative
AnswerA

The CISO owns the risk decision, weighing containment's operational and financial consequences against continued exposure. Isolating a critical server can halt revenue-generating services, so authority rests with the executive accountable for business impact rather than the technical responders.

Why this answer

The CISO is the decision-maker for business impact and authorizes containment actions.

25
MCQmedium

A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. A new marketing campaign document contains strategic pricing information that, if disclosed, could cause competitive harm. According to typical data classification practices, how should this document be classified?

A.Confidential
B.Internal
C.Restricted
D.Public
AnswerA

Confidential data is defined as information whose unauthorized disclosure could cause harm to the organization, such as competitive harm. Strategic pricing information fits this definition because its exposure could damage the company's market position. This classification aligns with the policy's description and ensures appropriate handling controls are applied.

Why this answer

Data classification policies typically define Confidential as information whose unauthorized disclosure could cause harm, including competitive harm. Strategic pricing information fits that definition, so it should be classified as Confidential. Public and Internal are too low, and Restricted is generally reserved for more severe impact, making Confidential the appropriate level for this document.

Exam trap

The trap here is assuming that any sensitive business information must be Restricted, when most policies reserve that level for the most severe impact and use Confidential for competitive harm.

26
MCQmedium

After resolving a security incident, the IR team conducts a lessons learned meeting. Which of the following are typical outputs of this post-incident activity? (Choose three.)

A.Recommendations for policy or procedure changes
B.Creation of new detection signatures for future incidents
C.Immediate containment of the incident
D.Development of metrics to measure response effectiveness
E.Updated incident response plan based on findings
AnswerA, D, E

The meeting generates recommendations for policy or procedure changes, such as revised escalation paths, access controls or detection rules. These outputs directly address root causes found during the incident, satisfying the post-incident objective of improving organisational defences.

Why this answer

Lessons learned leads to updating the IR plan, identifying metrics to measure performance, and recommending changes to policies.

27
MCQmedium

A security analyst is reviewing the organization's password policy, which currently requires a minimum of eight characters with complexity but no expiration. After a recent audit finding, management wants to align with modern best practices. Which change should the analyst recommend?

A.Allow users to choose any password of any length as long as it contains a special character
B.Reduce the minimum length to six characters and require changes every 30 days
C.Require passwords to be changed every 60 days and prohibit reuse of the last 24 passwords
D.Increase the minimum length to 14 characters and remove forced periodic expiration
AnswerD

This is correct because modern guidance favors longer passwords or passphrases over frequent forced changes, which often lead to predictable increments. A 14-character minimum significantly increases resistance to brute-force and credential-stuffing attacks. Removing expiration aligns with NIST guidance that discourages arbitrary rotation, reducing user frustration and weak password patterns.

Why this answer

Modern password guidance recommends longer minimum lengths, such as 14 characters, and discourages forced periodic expiration unless compromise is suspected. Longer passwords increase the effort required for brute-force attacks, while removing arbitrary expiration reduces predictable user behavior. This combination addresses the audit finding by aligning the policy with current best practices.

Exam trap

The trap here is assuming that frequent password expiration improves security, when it often leads to weaker, predictable passwords and is no longer recommended.

28
MCQmedium

An organization has implemented a new password policy requiring 12-character passwords with complexity. Which risk treatment option is this an example of?

A.Risk mitigation
B.Risk transfer
C.Risk acceptance
D.Risk avoidance
AnswerA

Enforcing 12-character complexity passwords applies an administrative control that lowers the likelihood of credential compromise, reducing overall risk exposure. This is mitigation, since the organisation acts to reduce risk rather than accept, transfer or avoid it.

Why this answer

Implementing controls to reduce risk is mitigation.

29
Multi-Selecthard

A SOC Tier 1 analyst is processing alerts. Which THREE tasks are typical for a Tier 1 analyst? (Select three.)

Select 3 answers
A.Conduct deep malware analysis
B.Develop new detection signatures
C.Execute basic investigation using standard tools
D.Monitor alerts and events
E.Perform initial triage and categorization
AnswersC, D, E

Tier 1 performs basic investigation with standard tooling such as SIEM queries and signature lookups, gathering enough evidence to confirm or dismiss an alert before escalating. Deeper forensics and remediation remain Tier 2 or Tier 3 responsibilities.

Why this answer

Option C is correct because Tier 1 analysts perform basic investigations with standard tools such as SIEM queries, log review, and endpoint/EDR lookups to validate alerts before escalation. Option D is correct because continuous monitoring of alerts and events from sources like SIEM, IDS/IPS, and EDR is a core Tier 1 responsibility. Option E is correct because initial triage and categorization—confirming true/false positive, assigning severity, and routing to the right queue—is exactly the Tier 1 role.

Option A does not belong because deep malware analysis (reverse engineering, sandboxing, code disassembly) is typically Tier 2/Tier 3 or a dedicated malware analyst function. Option B does not belong because developing new detection signatures or rules is an engineering/detection-content task, not a Tier 1 monitoring and triage duty.

30
Multi-Selectmedium

A SOC analyst is investigating a potential malware outbreak. Which THREE actions should the analyst take to preserve evidence? (Select three.)

Select 3 answers
A.Calculate a hash of the original drive before imaging
B.Reboot the system to clear memory
C.Document the chain of custody
D.Use a write blocker to create a forensic image
E.Run a full antivirus scan to remove malware
AnswersA, C, D

Hashing the original drive before imaging establishes integrity verification, proving the source was unaltered. This satisfies evidence preservation by enabling later comparison of the forensic image against the original hash, demonstrating the copy is forensically sound and unmodified.

Why this answer

Option A is correct because calculating a cryptographic hash (e.g., MD5 or SHA-256) of the original drive before imaging establishes a verifiable baseline that proves the forensic image is an exact, unaltered copy, which is essential for evidence integrity and admissibility. Option C is correct because documenting the chain of custody records who handled, accessed, and transferred the evidence, and when, ensuring the evidence's integrity can be attested in legal or disciplinary proceedings. Option D is correct because using a hardware or software write blocker prevents any writes to the source drive while creating a forensic image, preserving the original evidence in an unmodified state.

Option B is not correct because rebooting the system destroys volatile memory (RAM) contents such as running processes, network connections, and encryption keys, which are valuable evidence. Option E is not correct because running a full antivirus scan can modify or delete files and alter system state, contaminating the evidence rather than preserving it.

31
Multi-Selecteasy

A security analyst is establishing a data classification policy. Which TWO categories are commonly included in a data classification policy?

Select 2 answers
A.Archived
B.Encrypted
C.Backup
D.Confidential
E.Public
AnswersD, E

Confidential is a core classification tier, restricting data to authorised personnel only. It sits between internal and secret levels, satisfying the policy's need for a category governing sensitive business or personal information whose disclosure would cause harm.

Why this answer

Options D and E are correct because data classification policies typically define sensitivity levels that describe who may access the data and how it must be handled. 'Confidential' (D) is a standard classification label for data whose unauthorized disclosure could cause harm, so it is restricted to authorized personnel. 'Public' (E) is the opposite end of the spectrum, labeling data approved for unrestricted release to anyone. These sensitivity tiers are the core of a classification scheme, often alongside labels like Internal or Restricted. The unmarked options do not belong because 'Archived' (A) and 'Backup' (C) describe data lifecycle or storage states, not sensitivity levels, and 'Encrypted' (B) is a protective control applied to data rather than a classification category.

32
MCQmedium

An organization is implementing a new remote access policy. Which of the following is a key component that should be included in this policy?

A.Prohibition of personal device usage for any work
B.Mandatory use of social media for communication
C.Requirements for multi-factor authentication
D.Daily password changes for remote users
AnswerC

Multi-factor authentication directly mitigates credential compromise on remote connections, satisfying the policy's need to verify identity before granting access. Requiring MFA for all remote sessions addresses the primary risk that stolen passwords alone could otherwise permit unauthorised entry.

Why this answer

Remote access policies typically specify allowed methods (e.g., VPN), authentication requirements, and security controls.

33
MCQhard

A financial institution is implementing a data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. The security team must ensure that data labeled 'Restricted' receives the highest level of protection, including encryption, strict access controls, and monitoring. Which data classification level is typically subject to the most stringent regulatory requirements and requires the strongest security controls?

A.Internal
B.Confidential
C.Public
D.Restricted
AnswerD

Restricted is the highest classification level in this policy. It is reserved for data that requires the most stringent controls due to regulatory, legal, or business impact. In this scenario, the security team must apply the strongest protections to Restricted data, making it the correct classification for the most stringent requirements and strongest security controls.

Why this answer

In a typical data classification scheme, Restricted is the highest level and demands the most stringent security controls, including encryption, strict access, and monitoring. Public, Internal, and Confidential have progressively lower protection requirements. Since the policy defines Restricted as requiring the highest protection, that classification is the correct answer.

Exam trap

The trap here is assuming Confidential is always the highest level, but many policies add Restricted as a more stringent tier above Confidential.

34
MCQhard

A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. The analyst is asked to classify a document that contains the company's proprietary source code. According to typical data classification standards, which classification level is most appropriate?

A.Internal
B.Confidential
C.Restricted
D.Public
AnswerC

Restricted is the highest classification, reserved for data whose unauthorized disclosure would cause severe damage. Proprietary source code fits this category because its leak could destroy competitive advantage. This level typically enforces strict need-to-know access and strong encryption, aligning with the sensitivity of source code.

Why this answer

Proprietary source code is a critical asset that requires the highest level of protection. The Restricted classification is designed for such data, ensuring that only authorized personnel with a specific need can access it. This minimizes the risk of intellectual property theft and aligns with common data classification policies.

Exam trap

The trap here is assuming that Confidential is the highest level, when many policies include Restricted for the most sensitive data like trade secrets.

35
MCQmedium

Which role in the incident response process is primarily responsible for determining the business impact of an incident and making strategic decisions?

A.HR
B.Legal counsel
C.Incident handler
D.CISO
AnswerD

The CISO owns strategic incident decisions and business-impact assessment, translating technical findings into organisational risk. This role authorises containment, notification and recovery priorities, satisfying the stem's requirement for strategic decision-making authority rather than hands-on triage performed by analysts or the IR lead.

Why this answer

The CISO is the decision-maker who evaluates business impact and approves major actions.

36
MCQhard

A security manager is updating the organization's security awareness program after several incidents caused by employees inserting found USB drives. The manager wants a control that both reduces the likelihood of this behavior and provides a measurable metric for the awareness program. Which approach best meets both goals?

A.Require employees to sign an annual acceptable use policy acknowledgment stating they will not insert found USB drives.
B.Disable all USB mass storage through endpoint policy and rely solely on the technical control to prevent incidents.
C.Run periodic simulated USB drop tests and track the click or insertion rate over time as a key performance indicator.
D.Send a quarterly email reminding staff about the dangers of found USB drives and count the number of emails delivered.
AnswerC

Simulated USB drop tests directly measure whether employees exhibit the risky behavior in a controlled, ethical manner, and the insertion rate becomes a quantitative metric that can be trended across quarters. Combined with targeted training after each test, this approach reduces likelihood by reinforcing awareness. It satisfies both requirements: behavior change through education and a measurable indicator of program effectiveness that management can review.

Why this answer

Simulated USB drop tests both reduce risk through reinforced training and produce a quantitative metric, the insertion or click rate, that reflects real behavior. Technical blocks and policy acknowledgments may reduce exposure but do not measure whether employees have internalized the lesson. Quarterly reminders measured by delivery count track activity rather than effectiveness, so they fail the measurement requirement.

Exam trap

The trap here is accepting a distribution or completion metric, such as emails delivered or policies signed, as proof that awareness training changed risky behavior.

37
MCQeasy

A mid-size healthcare company has completed its annual review of security documentation. The CISO asks the governance team to align the documents into a clear hierarchy, where a single high-level document states the organization's overall security intentions and direction, and all subordinate documents must conform to it. Which document should the governance team treat as the highest-level authority?

A.Security standard
B.Security guideline
C.Security procedure
D.Security policy
AnswerD

A security policy is the top-level governance document that states management's intent, scope, and overall security objectives for the organization. Every standard, procedure, and guideline must be consistent with it. Because the scenario requires one high-level document that all subordinate documents conform to, the security policy is the correct authority to treat as the highest-level document.

Why this answer

The security policy is the foundational, management-approved statement of security intent, scope, and objectives, and it drives every standard, procedure, and guideline beneath it. Standards define mandatory requirements, procedures describe exact steps, and guidelines provide optional advice. Only the security policy functions as the single highest-level authority to which all subordinate documentation must conform.

Exam trap

The trap here is assuming that the most technically detailed document, such as a hardening standard or procedure, is the governing authority rather than recognizing that the policy sits at the top of the documentation hierarchy.

38
MCQmedium

An incident handler needs to preserve a hard drive from a compromised system. Which two actions are essential to maintain the integrity of the evidence?

A.Store the original drive in a Faraday bag
B.Copy files directly to an external drive using the operating system
C.Use a write blocker when creating the forensic image
D.Compute a cryptographic hash of the original drive before imaging
E.Boot the system from the hard drive to collect volatile data
AnswerC, D

A hardware or software write blocker intercepts write commands at the interface level, so the imaging tool reads the drive without altering a single sector. This preserves the original media's integrity, satisfying the requirement that evidence remain unmodified during acquisition.

Why this answer

A write blocker prevents any writes to the original drive, preserving its integrity during imaging. Option D is correct because computing a cryptographic hash (e.g., SHA-256) of the original drive before imaging creates a digital fingerprint that can be used later to verify that the forensic image is an exact copy and that no alterations occurred during acquisition or analysis. Both actions are essential to maintain evidence integrity and admissibility.

Exam trap

Cisco often tests the misconception that a Faraday bag preserves data integrity, when in fact it only prevents remote communication; the trap is confusing physical isolation (Faraday bag) with write protection (write blocker).

How to eliminate wrong answers

Option A is wrong because a Faraday bag is designed to block electromagnetic signals (e.g., RF, Wi-Fi, cellular) to prevent remote wiping or communication with the device, but it does not prevent physical write operations to the hard drive or preserve data integrity during imaging. Option B is wrong because copying files directly using the operating system modifies file metadata (e.g., access timestamps) and does not capture deleted files, slack space, or unallocated clusters; this violates forensic best practices for bit-for-bit imaging. Option E is wrong because booting from the compromised hard drive would alter the system state (e.g., writing to the page file, updating logs, modifying registry hives), destroying volatile data and potentially overwriting evidence; volatile data collection should be performed before powering off the system, not by booting from the drive.

39
MCQeasy

In the NIST SP 800-61 Rev 2 incident response process, which phase involves activities such as performing lessons learned and updating the incident response plan?

A.Preparation
B.Containment, Eradication, and Recovery
C.Detection and Analysis
D.Post-Incident Activity
AnswerD

Post-Incident Activity is the final NIST SP 800-61 Rev 2 phase, covering lessons learned reviews and incident response plan updates once containment, eradication and recovery are complete. It satisfies the stem's requirement for the phase where findings feed back into improved procedures, distinguishing it from Detection and Analysis or Containment, Eradication and Recovery.

Why this answer

Post-Incident Activity includes lessons learned, updating plans, and metrics.

40
MCQeasy

Which security policy defines acceptable use of an organization's IT resources, including internet browsing and email?

A.Password Policy
B.Information Security Policy
C.Remote Access Policy
D.Acceptable Use Policy (AUP)
AnswerD

An Acceptable Use Policy specifies permitted and prohibited behaviour for staff using organisational IT resources, covering internet browsing, email and hardware. It satisfies the stated scope directly, unlike policies addressing data classification, incident response or password construction.

Why this answer

AUP specifies what is acceptable and unacceptable use of IT resources.

41
MCQhard

A security analyst is reviewing the organization's data classification policy. The policy defines four levels: Public, Internal, Confidential, and Restricted. The analyst finds that a marketing team has stored a file containing customer credit card numbers on a shared drive accessible to all employees. The analyst must recommend the appropriate classification and handling for this file. What should the analyst recommend?

A.Classify as Public, because the customers consented to sharing their data.
B.Classify as Internal, because it is used by the marketing team for business purposes.
C.Classify as Restricted, encrypt the file, and limit access to authorized personnel only.
D.Classify as Confidential, apply password protection, and leave on the shared drive.
AnswerC

Credit card numbers are sensitive personal data subject to regulations like PCI DSS. They require the highest level of protection, typically Restricted. Encryption and strict access controls are necessary to prevent unauthorized disclosure. The analyst should recommend reclassifying the file and moving it to a secure location with access limited to those with a business need.

Why this answer

Customer credit card numbers are highly sensitive and regulated by PCI DSS. They should be classified as Restricted, the highest level in the policy, requiring encryption and strict access controls. Leaving them on a shared drive accessible to all employees is a serious violation.

The analyst should recommend reclassification and secure handling to prevent data breaches and regulatory penalties.

Exam trap

The trap here is underestimating the sensitivity of credit card numbers and choosing a lower classification like Confidential or Internal, when they actually require the highest level of protection.

42
MCQmedium

A security analyst is reviewing the organization's incident response plan. The plan defines several roles, including one responsible for coordinating all incident response activities and serving as the central point of communication. During a recent ransomware incident, this person was responsible for declaring the incident and ensuring that all stakeholders were informed. Which role does this describe?

A.Legal Advisor
B.SOC Tier 1 Analyst
C.Incident Handler
D.Incident Response Manager
AnswerD

The Incident Response Manager leads the incident response process, declares incidents, and coordinates communication among stakeholders. This role aligns with the scenario's description of declaring the incident and ensuring all stakeholders are informed. It is distinct from the tactical Incident Handler role.

Why this answer

The Incident Response Manager is responsible for the overall coordination of the incident response process. This includes declaring incidents, managing communication with stakeholders, and ensuring that the response follows the organization's policies. The other roles have more specific or tactical responsibilities that do not include overarching coordination.

Exam trap

The trap here is confusing the Incident Response Manager with the Incident Handler, assuming the person doing the technical work is also the one coordinating the entire response.

43
MCQhard

A security analyst needs to share threat intelligence with other organizations in a standardized, machine-readable format. Which combination of standards should the analyst use?

A.TAXII and MISP
B.STIX and TAXII
C.ISAC and STIX
D.OpenIOC and MISP
AnswerB

STIX provides the structured, machine-readable schema for describing indicators, threat actors and campaigns, while TAXII defines the transport protocol for exchanging that content between parties. Together they satisfy the requirement for standardised, automated threat-intelligence sharing.

Why this answer

STIX is a language for threat intelligence, and TAXII is a protocol for sharing it. They are commonly used together.

44
MCQhard

During an incident, a forensic analyst needs to preserve evidence from a compromised hard drive. Which of the following steps is essential to maintain the chain of custody?

A.Deleting unnecessary files to reduce data volume
B.Storing the hard drive in a standard office drawer
C.Documenting the date, time, and person handling the evidence
D.Creating a bit-for-bit copy without write-blocking
AnswerC

Chain of custody requires an unbroken record proving who held the evidence, when, and for what purpose. Documenting date, time, and handler creates this auditable trail, ensuring the drive's integrity can be attested in court and any tampering or gaps are detectable.

Why this answer

Chain of custody requires documenting each transfer, including who handled evidence and when. Write-blocking prevents alteration, and hashing verifies integrity. Documentation of transfers is key.

45
Multi-Selecthard

A security team is implementing a remote access policy. Which TWO controls should be included to ensure secure remote access?

Select 2 answers
A.Multifactor authentication (MFA)
B.Single sign-on (SSO)
C.Password expiration every 90 days
D.Virtual private network (VPN)
E.Guest network access
AnswersA, D

Multifactor authentication satisfies the remote access policy by requiring a second verification factor beyond a password, defeating credential theft and replay attacks. Combined with conditional access in Microsoft Entra ID, it enforces sign-in risk evaluation, ensuring only verified identities reach corporate resources over untrusted networks.

Why this answer

Option A (Multifactor authentication (MFA)) is correct because requiring a second factor beyond a password (e.g., TOTP, push notification, or FIDO2 security key) defends against credential theft, phishing, and password reuse, which are the primary risks for remote access. Option D (Virtual private network (VPN)) is correct because a VPN establishes an encrypted tunnel (e.g., IPsec/IKEv2 or TLS) between the remote endpoint and the corporate network, protecting data in transit from interception and enabling authenticated, policy-controlled access to internal resources. Option B (Single sign-on (SSO)) is not a security control that secures the remote connection itself; it improves user convenience and centralizes authentication but does not encrypt traffic or add a verification factor.

Option C (Password expiration every 90 days) is a legacy practice that is no longer recommended by NIST and does not compensate for weak or stolen credentials. Option E (Guest network access) is an isolated, untrusted network segment and does not provide secure access to corporate resources.

Exam trap

200-201 often tests the misconception that SSO or password expiration are sufficient for secure remote access, when in fact MFA and VPN are the foundational controls.

46
MCQeasy

A SOC manager is drafting the organization's incident response plan and wants to align it with the NIST SP 800-61 Rev. 2 lifecycle so that phases are clearly defined for auditors. Which sequence correctly represents the four phases of the incident response lifecycle as described in NIST SP 800-61 Rev. 2?

A.Identification, Containment, Eradication, Recovery
B.Preparation, Prevention, Detection, Response
C.Planning, Execution, Monitoring, Closure
D.Preparation; Detection and Analysis; Containment, Eradication, and Recovery; Post-Incident Activity
AnswerD

NIST SP 800-61 Rev. 2 defines exactly these four phases in this order, beginning with preparation before an incident occurs, then detection and analysis, then containment, eradication, and recovery, and finally post-incident activity. Adopting this structure gives the SOC manager a recognized framework that auditors can map to, and it ensures lessons learned feed back into preparation for continuous improvement.

Why this answer

NIST SP 800-61 Rev. 2 organizes incident response into four phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity. A plan built on this structure gives clear entry and exit criteria for each phase, supports role assignment, and provides auditors with a recognizable mapping. The other sequences either describe only response sub-steps or borrow generic project management terms that do not match the standard.

Exam trap

The trap here is assuming the famous containment, eradication, and recovery steps are separate top-level phases rather than a single combined phase in the NIST SP 800-61 Rev. 2 lifecycle.

47
MCQeasy

An employee is suspected of using company resources to access inappropriate websites. Which security policy most directly addresses this behavior?

A.Acceptable Use Policy (AUP)
B.Remote access policy
C.Information security policy
D.Password policy
AnswerA

An Acceptable Use Policy defines permitted employee use of company systems and networks, explicitly prohibiting access to inappropriate websites. It directly governs the behaviour described, making it the policy that addresses misuse of company resources for browsing inappropriate content.

Why this answer

The Acceptable Use Policy defines acceptable use of company resources, including internet usage.

48
MCQmedium

Which of the following are responsibilities of the legal counsel role during incident response? (Choose two.)

A.Determining data breach notification requirements
B.Communicating with the media
C.Conducting technical analysis of malware
D.Approving financial expenditures for containment
E.Issuing a legal hold to preserve relevant data
AnswerA, E

Legal counsel advises on legal obligations to notify affected parties.

Why this answer

Legal counsel advises on breach notification requirements and can place legal holds to preserve evidence for litigation.

49
MCQhard

A security operations center (SOC) manager is developing a playbook for handling phishing incidents. The playbook must specify the first action an analyst should take upon receiving a reported phishing email. Which action should be performed first according to standard incident response procedures?

A.Notify law enforcement about the phishing attempt
B.Isolate the recipient's workstation from the network
C.Preserve the email and analyze its headers and attachments
D.Delete the email from all mailboxes
AnswerC

The first step in phishing response is to preserve the email as evidence and analyze its headers, URLs, and attachments to confirm malicious intent and identify indicators. This analysis informs subsequent actions such as blocking senders, quarantining similar emails, and notifying affected users. It aligns with standard incident response procedures that prioritize identification and containment planning.

Why this answer

Standard incident response procedures for phishing begin with preserving and analyzing the reported email to confirm maliciousness and extract indicators. This step enables accurate containment and remediation, such as blocking malicious domains and quarantining similar messages. Isolating, deleting, or notifying law enforcement are subsequent actions that depend on the initial analysis.

Exam trap

The trap here is jumping to containment or remediation actions before validating the incident and gathering evidence, which can destroy critical information.

50
MCQmedium

A SOC analyst at Tier 1 receives an alert for a known malware signature. After initial investigation, the analyst finds that the alert is a false positive caused by an outdated signature. What should the analyst do next?

A.Escalate the alert to Tier 2 for further analysis
B.Update the signature database on the security tools
C.Initiate the containment process
D.Close the alert and document the finding
AnswerD

With the alert confirmed as a false positive from an outdated signature, no genuine incident exists, so the analyst closes it and documents the finding. This preserves the audit trail and supports later tuning of the detection signature.

Why this answer

When a Tier 1 analyst determines an alert is a false positive caused by an outdated signature, the correct action is to close the alert and document the finding so the signature can be reviewed and tuned. Escalating or containing would waste resources on a non-incident. Documentation ensures the false positive is tracked and the detection rule can be improved.

Exam trap

200-201 often tests the boundary between triage and response — candidates pick containment or escalation because they sound 'safe,' but the exam expects recognition that a confirmed false positive is closed and documented, not escalated or acted upon.

How to eliminate wrong answers

Option A is wrong because escalating a confirmed false positive to Tier 2 wastes Tier 2 resources and violates triage efficiency — escalation is reserved for unresolved or suspicious alerts. Option C is wrong because containment (isolating hosts, blocking IPs) is an incident response action that should never be triggered by a false positive, as it could disrupt business operations unnecessarily. Option B is wrong because a Tier 1 analyst typically does not have authority or responsibility to update the signature database; that is a detection engineering or signature management task, and the immediate step is to close and document.

51
MCQhard

A security analyst is reviewing the organization's incident response plan and notices that the 'Lessons Learned' phase is scheduled only after major incidents. The analyst recommends that this phase be conducted after all incidents, regardless of severity. What is the primary benefit of this recommendation?

A.It ensures that all incidents are reported to regulatory authorities.
B.It eliminates the need for a formal incident response plan.
C.It reduces the time required for the containment phase of future incidents.
D.It helps identify minor issues that could be precursors to major incidents.
AnswerD

Conducting lessons learned after every incident, even minor ones, helps uncover small gaps or weaknesses that could escalate into major incidents if left unaddressed. This proactive approach improves the overall security posture and prevents future incidents. It also fosters a culture of continuous improvement, where even small incidents are analyzed for root causes and corrective actions.

Why this answer

The primary benefit of conducting lessons learned after every incident is to identify minor issues that could be early indicators of larger problems. This practice enables continuous improvement and helps prevent minor incidents from escalating. It does not directly reduce containment time, ensure regulatory reporting, or replace the need for an incident response plan.

Exam trap

The trap here is assuming that lessons learned is only about post-incident documentation for major events, when its real value is in uncovering small weaknesses that could lead to bigger incidents.

52
MCQeasy

A company is updating its security policy to align with the principle of least privilege. The IT director asks the security analyst to recommend a control that enforces this principle for user access to a financial application. Which control should the analyst recommend?

A.Single sign-on (SSO) with multifactor authentication (MFA).
B.Mandatory access control (MAC) using sensitivity labels on all data.
C.Discretionary access control (DAC) where data owners set permissions.
D.Role-based access control (RBAC) that grants permissions based on job functions.
AnswerD

RBAC enforces least privilege by assigning permissions to roles, not individuals, and users are granted only the roles needed for their job. This limits access to what is required to perform duties. It is a standard method to implement least privilege in applications. The financial application scenario fits RBAC because access can be tied to job functions like teller, auditor, or manager.

Why this answer

The principle of least privilege requires that users have only the minimum access necessary to perform their job functions. Role-based access control (RBAC) achieves this by defining roles with specific permissions and assigning users to roles. This limits access based on job needs and simplifies administration.

Other controls like MAC, DAC, or SSO/MFA do not directly enforce least privilege for application access.

Exam trap

The trap here is confusing authentication controls like SSO and MFA with authorization controls that enforce least privilege, when the question specifically asks for an access control method to limit permissions.

53
MCQmedium

A security manager is developing a business continuity plan (BCP) and needs to determine the maximum tolerable downtime (MTD) for a critical order-processing system. The system generates $10,000 in revenue per hour. If the system is down for more than 4 hours, the company will lose a key customer. What is the MTD for this system?

A.The MTD cannot be determined from the information given.
B.24 hours
C.1 hour
D.4 hours
AnswerD

The maximum tolerable downtime (MTD) is the longest period that a system can be unavailable before unacceptable consequences occur. In this scenario, the company will lose a key customer if the system is down for more than 4 hours, so the MTD is 4 hours. This is the threshold beyond which the business impact becomes intolerable.

Why this answer

The maximum tolerable downtime (MTD) is the longest time a system can be offline before the business suffers unacceptable consequences. Here, the loss of a key customer after 4 hours defines that threshold, so the MTD is 4 hours. Revenue loss per hour is relevant for cost analysis but does not change the MTD.

Exam trap

The trap here is confusing the MTD with the recovery time objective (RTO) or using revenue loss to calculate a different value, when the MTD is directly stated by the business impact threshold.

54
Multi-Selectmedium

A security analyst is collecting evidence from a compromised system for legal proceedings. Which TWO actions are critical to preserve the integrity of the evidence?

Select 2 answers
A.Store the evidence in a public folder for easy access
B.Compute a cryptographic hash of the original drive before imaging
C.Delete any sensitive files to protect privacy
D.Run the system normally to capture volatile data
E.Use a write-blocker when creating a forensic image
AnswersB, E

Hashing the original drive before imaging creates a verifiable baseline; any later hash mismatch on the copy proves the data was altered. This satisfies the admissibility constraint by demonstrating the evidence remained unmodified from seizure through analysis.

Why this answer

Option B is correct because computing a cryptographic hash (e.g., SHA-256 or MD5) of the original drive before imaging establishes a verifiable baseline value that can later be compared against the hash of the forensic image to prove the copy is bit-for-bit identical and unaltered, which is essential for evidence admissibility. Option E is correct because a hardware or software write-blocker prevents any write operations from reaching the source drive during imaging, ensuring the original evidence is not modified and preserving its integrity for legal proceedings. Option A is wrong because storing evidence in a public folder exposes it to tampering, unauthorized access, and contamination, destroying the chain of custody.

Option C is wrong because deleting files alters the original evidence and constitutes spoliation. Option D is wrong because running the system normally modifies the drive and volatile state, contaminating the evidence rather than preserving it.

55
MCQmedium

An organization classifies data into Public, Internal, Confidential, and Restricted tiers. A developer needs to place a dataset containing customer payment card numbers into the correct tier and apply the required handling controls. According to common data classification practices, which tier and control combination is most appropriate?

A.Restricted, with encryption, strict need-to-know access, and audit logging
B.Confidential, with encryption at rest and in transit
C.Internal, because the data is used only by employees
D.Public, because the numbers are only partial card values
AnswerA

Restricted is the highest sensitivity tier and is appropriate for regulated data such as payment card numbers, which PCI DSS requires to be encrypted and tightly access-controlled. Applying encryption, least-privilege access, and audit logging aligns with both the classification scheme and regulatory expectations. This combination protects the data and provides the accountability needed if a breach occurs.

Why this answer

Payment card numbers are regulated under PCI DSS and represent a high-impact asset if disclosed, so they belong in the most restrictive tier the organization defines. Restricted classification paired with encryption, need-to-know access, and audit logging satisfies both internal policy and regulatory expectations. Lower tiers such as Internal, Confidential, or Public would apply weaker controls than the data warrants and could create compliance exposure.

Exam trap

The trap here is assuming that because only employees use the data it can be labeled Internal, when regulatory sensitivity rather than audience determines the classification tier.

56
MCQmedium

Which threat intelligence sharing standard defines a language and format for representing structured threat information, such as indicators and campaigns?

A.STIX
B.MISP
C.TAXII
D.OpenIOC
AnswerA

STIX (Structured Threat Information Expression) provides a standardised language and serialisation format for structured threat intelligence, covering indicators, campaigns, threat actors and relationships. It satisfies the requirement for a sharing standard that represents structured threat information, unlike transport protocols such as TAXII.

Why this answer

STIX is a standardized language for describing threat intelligence, while TAXII is the protocol to share it.

57
MCQmedium

A financial services company must retain security event logs for a period defined by its policy and applicable regulations. The security architect is documenting how long different log sources must be kept and where. Which statement best reflects a sound log retention practice for security operations?

A.Retain only logs that the SIEM has already correlated into alerts, discarding raw events to save space.
B.Delete logs after 24 hours to reduce the risk of exposing sensitive information in the event of a breach.
C.Define retention periods per log source based on regulatory and business requirements, and store logs centrally with integrity protection.
D.Retain all logs indefinitely on the source system to guarantee availability for any future investigation.
AnswerC

Sound practice is to map each log source to a retention period derived from legal, regulatory, and investigative needs, then centralize storage so logs survive host rebuilds. Central storage with integrity protection, such as write-once or hashed archives, preserves evidentiary value. This approach balances cost with the ability to investigate incidents that may be discovered months after initial activity, and it supports audits by documenting the rationale for each period.

Why this answer

Effective log retention ties each source to a defined period justified by regulation and business need, then centralizes storage with integrity protection so logs remain available and trustworthy. Indefinite retention on source systems, extremely short deletion windows, or keeping only correlated alerts all undermine investigations and compliance. The chosen approach supports both retrospective hunting and evidentiary requirements.

Exam trap

The trap here is equating storage savings with good retention practice, leading to keeping only alerts or deleting logs too quickly.

58
MCQmedium

A security analyst is reviewing the chain of custody form for a laptop seized from an employee suspected of intellectual property theft. The form shows the laptop was collected by the IT manager, transported to a storage room, and later examined by an outside forensics firm. The analyst notices that the form lacks signatures for the transfer between the IT manager and the storage room custodian. What is the most likely impact of this omission on the investigation?

A.The outside forensics firm must re-examine the laptop from scratch to restore integrity.
B.The forensic examination results will be automatically inadmissible in court.
C.The IT manager will be held personally liable for any data loss from the laptop.
D.The evidence may be challenged as tampered or unauthenticated in legal proceedings.
AnswerD

A complete chain of custody requires documented, signed transfers at every handoff. Missing signatures for the IT manager to storage room transfer creates a gap where unauthorized access or tampering could have occurred. This weakens the evidence's admissibility and credibility. In legal proceedings, opposing counsel can argue the evidence was not properly controlled, potentially leading to exclusion or reduced weight.

Why this answer

A chain of custody is a chronological documentation of evidence seizure, custody, transfer, and analysis. Each transfer must be signed and dated to prove the evidence was not tampered with. Missing signatures create an unaccounted period, which undermines the evidence's authenticity.

Courts may exclude or discount such evidence, so the correct impact is that it may be challenged as tampered or unauthenticated.

Exam trap

The trap here is assuming that any chain of custody error makes evidence automatically inadmissible, when in reality it typically affects the weight or credibility of the evidence rather than causing automatic exclusion.

59
MCQeasy

A healthcare organization stores patient records and must comply with the HIPAA Security Rule. The CISO wants to document the types of safeguards that protect data through encryption, access controls, and audit logging. Which category of safeguards under the HIPAA Security Rule covers these controls?

A.Organizational requirements
B.Technical safeguards
C.Physical safeguards
D.Administrative safeguards
AnswerB

Technical safeguards under the HIPAA Security Rule specifically include access control, audit controls, integrity controls, person or entity authentication, and transmission security such as encryption. Encryption at rest, role-based access, and audit logging are technology-based mechanisms that protect electronic protected health information. This category directly matches the controls the CISO wants documented for protecting patient records.

Why this answer

The HIPAA Security Rule groups safeguards into administrative, physical, and technical categories. Encryption, access controls, and audit logging are technology-based protections applied to electronic protected health information, which places them squarely in the technical safeguards category. Administrative safeguards involve policies and workforce management, while physical safeguards involve facility and device protections, so neither fits the described controls.

Exam trap

The trap here is assuming that any documented security control is an administrative safeguard, when technology-enforced controls such as encryption and audit logging are classified as technical safeguards.

60
Multi-Selecteasy

Which TWO are examples of risk treatment options? (Select two.)

Select 2 answers
A.Neglect
B.Mitigate
C.Ignore
D.Accept
E.Amplify
AnswersB, D

Implementing controls to reduce risk.

Why this answer

Mitigate (B) is a recognized risk treatment option because it involves applying controls or countermeasures to reduce the likelihood and/or impact of a risk to an acceptable level. Accept (D) is also a recognized risk treatment option, meaning the organization acknowledges the risk and decides to retain it without additional controls, typically when the cost of treatment outweighs the benefit or the risk is within tolerance. The other options are not standard risk treatment categories: Neglect (A) and Ignore (C) imply simply disregarding a risk without a formal, documented decision, which is not a valid treatment strategy, and Amplify (E) is not a recognized risk treatment option since treatment aims to reduce or transfer risk, not increase exposure.

61
MCQmedium

A security manager is drafting an incident response policy and wants to ensure that the organization can legally monitor employee communications during an investigation. The manager asks the legal team what element must be included in the employee handbook and policy documents to support this capability. Which element is most critical?

A.A provision that all incident response activities are exempt from regulatory oversight
B.A requirement that employees report all security incidents within one hour of discovery
C.A statement that employees have no expectation of privacy when using corporate systems
D.A clause requiring employees to surrender personal devices for forensic imaging at any time
AnswerC

This is correct because monitoring is legally defensible when employees are clearly informed that corporate systems are subject to monitoring and that they should not expect privacy. This notice, often included in an Acceptable Use Policy or employee handbook, establishes consent and reduces legal risk. Without it, monitoring during an investigation could violate privacy laws or employment agreements.

Why this answer

The legal basis for monitoring employee communications is established by clearly informing employees that corporate systems are monitored and that privacy should not be expected. This notice, typically embedded in an Acceptable Use Policy or handbook, demonstrates consent and supports investigations. Reporting deadlines and device surrender clauses address different concerns and do not provide the same legal foundation for monitoring.

Exam trap

The trap here is confusing incident reporting requirements or device seizure clauses with the notice-and-consent language that actually legitimizes monitoring of corporate communications.

62
MCQmedium

A security analyst discovers that a former employee's user account remains active 45 days after termination, and audit logs show that the account was used to access a file server twice in the past week. Which element of the access control lifecycle was MOST directly violated?

A.Credential rotation
B.Account deprovisioning
C.Privilege escalation review
D.Account provisioning
AnswerB

Deprovisioning is the lifecycle stage that removes or disables access when a user leaves the organization. The account should have been disabled on the employee's last day, but it remained active for 45 days and was used to reach a file server. This directly indicates a breakdown in the termination workflow, such as missing HR-to-IT notifications or absent automated account-disable rules tied to HR status changes.

Why this answer

The account of a terminated employee should have been disabled as part of the offboarding process. Its continued activity 45 days later shows the deprovisioning step of the identity lifecycle failed. Effective programs integrate HR termination events with identity management so accounts are disabled automatically, and they run periodic access reviews to catch accounts that slip through manual processes.

Exam trap

The trap here is assuming any access problem is a permissions problem, when the real issue is that the identity should no longer have existed at all.

63
MCQmedium

A security analyst at a SOC Tier 1 receives an alert about a potential malware infection on a user's workstation. What is the primary responsibility of the Tier 1 analyst in this scenario?

A.Coordinate with legal counsel for data breach notification
B.Conduct initial triage and basic investigation
C.Develop new detection signatures
D.Perform deep forensic analysis of the malware
AnswerB

Tier 1 analysts perform initial triage and basic investigation, validating the alert, gathering preliminary data, and escalating confirmed incidents. This matches the primary responsibility for a potential malware infection, as deeper forensics and remediation belong to Tier 2 or Tier 3.

Why this answer

Tier 1 analysts monitor alerts, perform initial triage, and escalate if needed. They conduct basic investigation.

64
MCQhard

During the containment phase of an incident, the IR team decides to power off a compromised server to prevent further damage. However, they later realize that this action may have destroyed volatile evidence. According to best practices, what should the team have done instead?

A.Disconnect the server from the network but leave it running
B.Perform a live forensic image of the server's memory before powering off
C.Immediately power off the server without any imaging
D.Skip evidence collection and focus solely on containment
AnswerB

Memory contents — running processes, network connections, encryption keys — are volatile and lost on power-off. Capturing a live memory image preserves that evidence for analysis, whereas shutting the server down destroys it irrecoverably, so imaging should precede containment.

Why this answer

Short-term containment should preserve evidence; live imaging captures volatile data before power-off.

65
MCQhard

A security analyst is reviewing an incident response policy that requires the team to preserve evidence for potential legal action. The analyst notices that the policy does not address how to handle evidence when a compromised system must be rebooted to restore services. What should the analyst recommend to balance evidence preservation with operational recovery?

A.Shut down the system and store it in a secure room without further analysis
B.Continue running the compromised system indefinitely to observe attacker behavior
C.Capture volatile memory and disk images before rebooting, and document the sequence of actions
D.Reboot immediately to restore services and collect evidence afterward from backups
AnswerC

This is correct because volatile data such as RAM contents and running processes are lost on reboot, so capturing memory and disk images first preserves critical evidence. Documenting the sequence maintains chain of custody. This approach balances the need to restore services with the legal requirement to preserve evidence, which the current policy fails to address.

Why this answer

When a compromised system must be rebooted, capturing volatile memory and disk images beforehand preserves evidence that would otherwise be lost. Documenting each action maintains chain of custody and supports legal admissibility. This balanced approach allows services to be restored without sacrificing the integrity of the investigation, addressing the gap in the current policy.

Exam trap

The trap here is assuming that rebooting first and collecting evidence later is acceptable, when volatile data such as RAM contents would be permanently lost.

66
MCQmedium

An organization uses STIX and TAXII to share threat intelligence with an ISAC. What is the purpose of TAXII in this scenario?

A.It stores threat intelligence locally
B.It is a platform for malware analysis
C.It provides a method to transport threat intelligence
D.It defines the format for threat indicators
AnswerC

TAXII defines the application-layer protocol and services for exchanging cyber threat intelligence over HTTPS, carrying STIX-formatted content between parties. It satisfies the ISAC sharing requirement by providing the transport mechanism, whereas STIX supplies the structured data format itself.

Why this answer

TAXII is a protocol for exchanging STIX data.

67
MCQmedium

A security analyst is investigating a potential data breach. They need to preserve evidence for legal proceedings. Which action should the analyst take to ensure the integrity of the data?

A.Run antivirus scans on the affected system
B.Use a write blocker when creating a forensic image
C.Delete suspicious files to contain the threat
D.Copy files to a network share without write protection
AnswerB

A write blocker enforces a hardware or software read-only mount, preventing any modification to the source drive during imaging. This preserves bit-for-bit integrity and maintains the chain of custody, satisfying the legal requirement that evidence remain unaltered and admissible in proceedings.

Why this answer

A write blocker is a hardware or software tool that prevents any write operations to the storage device while a forensic image is being created, preserving the original evidence and ensuring the image is a bit-for-bit copy. This maintains the integrity and admissibility of evidence in legal proceedings.

Exam trap

The trap is thinking that any copy of data is sufficient for forensics; candidates underestimate how even read operations can alter metadata, and they may choose antivirus scanning or deletion as 'containment' steps that actually destroy evidence.

How to eliminate wrong answers

Option A is wrong because running antivirus scans modifies file metadata and potentially quarantines files, altering the evidence. Option C is wrong because deleting suspicious files destroys evidence and violates chain-of-custody requirements. Option D is wrong because copying files to a network share without write protection can modify timestamps and data, and does not produce a forensically sound image.

68
MCQeasy

A security analyst is reviewing the organization's security policy framework. The analyst notes that the policy defines the acceptable use of company assets, including computers, networks, and data. Which document typically outlines the rules for employee behavior when using these assets?

A.Service Level Agreement (SLA)
B.Non-Disclosure Agreement (NDA)
C.Incident Response Plan (IRP)
D.Acceptable Use Policy (AUP)
AnswerD

The Acceptable Use Policy (AUP) defines how employees may use company assets, including computers and networks. It sets expectations for behavior and consequences for violations. In this scenario, the AUP is the document that outlines these rules, making it the correct choice.

Why this answer

The Acceptable Use Policy (AUP) is designed to outline the rules and guidelines for using company assets. It typically covers what is allowed and prohibited, and the consequences of violations. This aligns with the scenario's requirement to define acceptable use of computers, networks, and data.

Exam trap

The trap here is confusing the AUP with other policies like the NDA, which also govern behavior but focus on confidentiality rather than asset use.

69
MCQeasy

A security administrator is configuring a firewall rule set to control traffic between the corporate network and the internet. The policy states that only web browsing (HTTP and HTTPS) should be allowed outbound, and all other outbound traffic should be denied. Which type of security control is this an example of?

A.Preventive control
B.Detective control
C.Compensating control
D.Corrective control
AnswerA

A preventive control is designed to stop unwanted actions or events before they occur. By explicitly allowing only HTTP and HTTPS outbound and denying all other traffic, the firewall rule set prevents unauthorized outbound connections. This aligns with the definition of a preventive control, as it blocks potentially malicious or non-compliant traffic from leaving the network.

Why this answer

The firewall rule set is a preventive control because it enforces the policy by blocking all outbound traffic except HTTP and HTTPS before it can leave the network. Preventive controls are proactive measures that stop unwanted actions. Detective controls identify events, corrective controls remediate after incidents, and compensating controls are alternatives when primary controls are not feasible.

Exam trap

The trap here is confusing logging or alerting features of a firewall with its primary function, which in this scenario is to block traffic, making it preventive.

70
Multi-Selecthard

A hospital's security team is updating its data handling policy. The compliance officer asks which two classification labels are most appropriate for a patient's electronic protected health information (ePHI) under a typical data classification scheme aligned with HIPAA expectations. (Choose two.)

Select 2 answers
A.Confidential
B.Internal Use Only
C.Unclassified
D.Public
E.Restricted
AnswersA, E

Confidential is widely used for sensitive personal or business data requiring protection from unauthorized disclosure, and ePHI commonly falls into this tier when an organization uses a three- or four-level scheme. Labeling ePHI as Confidential ensures encryption, access controls, and handling rules apply, and it aligns with HIPAA's expectation that protected health information be safeguarded. It is therefore an appropriate classification label alongside Restricted.

Why this answer

In a typical data classification scheme, ePHI belongs in the highest sensitivity tiers because unauthorized disclosure causes regulatory penalties and patient harm. Restricted and Confidential are the two labels that mandate encryption, strict access control, and handling procedures consistent with HIPAA. Public, Internal Use Only, and Unclassified all imply weaker or no protections, so they cannot be applied to patient health information in this policy.

Exam trap

The trap here is treating Internal Use Only as sufficient for regulated health data simply because ePHI should stay inside the organization.

71
MCQeasy

During which phase of the NIST SP 800-61 Rev 2 incident response process should an organization develop and exercise the incident response plan?

A.Preparation
B.Post-Incident Activity
C.Detection and Analysis
D.Containment, Eradication, and Recovery
AnswerA

Preparation is the phase where organisations build incident response capability before incidents occur, including developing the plan, defining roles, and conducting exercises. NIST SP 800-61 Rev 2 places plan creation and training squarely here, satisfying the stem's requirement to both develop and exercise the plan ahead of any detection or containment activity.

Why this answer

The Preparation phase of NIST SP 800-61 Rev 2 covers establishing the incident response capability, including developing the IR plan, acquiring tools, training staff, and exercising the plan through tabletop and functional exercises. Exercising the plan before an incident occurs is explicitly a Preparation activity, not something done during or after an event.

Exam trap

The trap here is confusing 'exercising the plan' with 'improving the plan after an incident' — candidates often pick Post-Incident Activity because both involve the plan, but only Preparation covers initial development and drills.

How to eliminate wrong answers

Option B is wrong because Post-Incident Activity focuses on lessons learned and improving the plan after an incident, not on developing and exercising it initially. Option C is wrong because Detection and Analysis is where the team identifies and scopes an active incident, not where the plan is authored or drilled. Option D is wrong because Containment, Eradication, and Recovery is the execution phase where the plan is applied to a live incident, not where it is developed or exercised.

72
MCQmedium

A security analyst is reviewing the organization's incident response plan and notices that it does not specify how to handle a situation where a zero-day vulnerability is exploited before a patch is available. The analyst wants to recommend a proactive measure that aligns with the NIST SP 800-61 revision 2 and the CyberOps Associate curriculum. Which of the following should the analyst recommend?

A.Deploy a next-generation firewall with signature-based detection to block all known exploits.
B.Conduct regular vulnerability scans to identify and remediate all unpatched systems.
C.Develop and maintain a playbook for zero-day incident response that includes isolation, monitoring, and temporary workarounds.
D.Implement a bug bounty program to incentivize external researchers to report vulnerabilities.
AnswerC

A zero-day playbook provides predefined steps for containment, such as network segmentation, increased monitoring, and applying vendor-provided mitigations or workarounds. This aligns with NIST SP 800-61's recommendation to have specific procedures for handling incidents when patches are unavailable. It ensures a coordinated and efficient response, reducing the time an attacker has to operate and limiting damage.

Why this answer

The correct recommendation is to develop a zero-day incident response playbook. NIST SP 800-61 emphasizes the importance of having specific procedures for incidents that do not have immediate fixes. A playbook outlines steps for containment, monitoring, and applying temporary mitigations, which are critical when a patch is unavailable.

This proactive measure ensures the organization can respond effectively and minimize impact during a zero-day attack.

Exam trap

The trap here is assuming that vulnerability scanning or signature-based firewalls can protect against zero-day exploits, when they are ineffective without known signatures or patches.

73
MCQhard

A security manager is drafting a service level agreement (SLA) with a cloud service provider. The SLA must specify the maximum acceptable time for the provider to restore service after a disruption. Which metric should the manager include in the SLA to define this requirement?

A.Mean Time To Repair (MTTR)
B.Mean Time Between Failures (MTBF)
C.Recovery Point Objective (RPO)
D.Recovery Time Objective (RTO)
AnswerD

RTO is the maximum acceptable time to restore a service after a disruption. It directly defines the target for service restoration, making it the correct metric for the SLA. The manager should specify RTO to ensure the provider commits to a restoration timeframe that meets business needs. This aligns with the scenario's requirement.

Why this answer

The Recovery Time Objective (RTO) defines the maximum acceptable time to restore a service after a disruption, making it the correct metric for the SLA. RPO addresses data loss, while MTBF and MTTR are reliability and repair averages, not restoration targets. The manager should specify RTO to ensure the provider meets business continuity requirements.

Exam trap

The trap here is confusing RTO with RPO or with average repair times like MTTR, which do not define the maximum acceptable restoration time.

74
Multi-Selectmedium

Which TWO are components of the NIST SP 800-61 Rev 2 Preparation phase? (Select two.)

Select 2 answers
A.Conducting lessons learned
B.Developing an incident response plan
C.Containing the incident
D.Creating an incident response team
E.Identifying indicators of compromise
AnswersB, D

Drafting the incident response plan belongs to Preparation: it defines scope, roles, communication paths and playbooks before any incident occurs, satisfying the phase's requirement to establish capability in advance rather than during detection or containment.

Why this answer

Option B (Developing an incident response plan) is correct because NIST SP 800-61 Rev 2 places the creation of a formal, written IR plan—covering mission, goals, roles, communication paths, and escalation procedures—squarely in the Preparation phase, before any incident occurs. Option D (Creating an incident response team) is also correct because staffing and organizing the CSIRT (with defined roles, authority, and on-call procedures) is a core Preparation activity that must exist before incidents can be handled. By contrast, option A (Conducting lessons learned) belongs to the Post-Incident Activity phase, where the team reviews what happened and improves the plan.

Option C (Containing the incident) is part of the Detection and Analysis/Containment, Eradication, and Recovery handling phase, not Preparation. Option E (Identifying indicators of compromise) is a Detection and Analysis activity, since IoCs are used to discover and validate incidents rather than to prepare for them.

75
MCQmedium

A company's security policy requires that all data classified as 'Confidential' must be encrypted at rest and in transit. This requirement is part of which policy?

A.Remote Access Policy
B.Password Policy
C.Data Classification Policy
D.Acceptable Use Policy
AnswerC

A Data Classification Policy defines the sensitivity tiers and mandates the handling controls each tier requires, including encryption at rest and in transit for 'Confidential' data. It is the governing document that translates classification labels into enforceable protection requirements, satisfying the stem's demand that classified data carry specific encryption obligations.

Why this answer

The requirement to encrypt 'Confidential' data is a direct outcome of a data classification policy, which defines categories (e.g., Public, Internal, Confidential, Restricted) and mandates specific security controls for each category. Encryption at rest and in transit is a typical control for the 'Confidential' tier, ensuring data is protected using mechanisms like AES-256 for storage and TLS 1.2+ for transmission.

Exam trap

Cisco often tests the distinction between a policy that defines data sensitivity levels (data classification) and a policy that implements access controls (remote access), leading candidates to confuse the encryption requirement with the method of access.

How to eliminate wrong answers

Option A is wrong because a remote access policy governs how users connect from external networks (e.g., VPN protocols, multi-factor authentication), not the classification-based encryption requirements for data. Option B is wrong because a password policy defines rules for password creation, complexity, and expiration (e.g., minimum length, special characters), not encryption of data based on sensitivity. Option D is wrong because an acceptable use policy outlines permitted and prohibited behaviors for company resources (e.g., browsing restrictions, software installation), not data encryption mandates tied to classification labels.

Page 1 of 2 · 111 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security Policies and Procedures questions.