Courseiva

200-201 · topic practice

Security Policies and Procedures practice questions

This domain covers incident response per NIST SP 800-61 (preparation, detection and analysis, containment/eradication/recovery, post-incident), plus policy documents such as AUP, data classification, and evidence handling. Questions are scenario-based: you identify the correct IR phase, choose containment actions that preserve volatile data, and apply chain-of-custody and forensic integrity practices.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Security Policies and Procedures

What the exam tests

What to know about Security Policies and Procedures

Be able to place a scenario in the correct NIST SP 800-61 phase, pick containment that preserves volatile evidence, and describe forensic integrity steps. The single most important thing: never destroy volatile data before capturing it, and document chain of custody.

Mapping triage and alert validation to the NIST SP 800-61 detection and analysis phase

Ordering containment, eradication, and recovery activities during a live incident

Recognizing AUP content: acceptable use, monitoring, and consequences of violations

Preserving evidence via write blockers, hashing, and documented chain of custody

Watch out for

Common Security Policies and Procedures exam traps

  • ▸Confusing containment with eradication or recovery; powering off a host is containment but destroys volatile memory evidence.
  • ▸Treating triage as preparation; initial alert validation and scoping belong to detection and analysis.
  • ▸Assuming an AUP grants technical controls; it states user expectations and sanctions, not firewall or EDR configuration.

Practice set

Security Policies and Procedures questions

20 questions · select your answer, then reveal the explanation

During the Detection and Analysis phase of incident response, a SOC Tier 1 analyst identifies a potential malware infection on a critical server. What is the FIRST action the analyst should take according to NIST SP 800-61 Rev 2?

In the context of risk management, which THREE are valid risk treatment options?

Which TWO standards/protocols are directly associated with threat intelligence sharing as defined by the CyberOps Associate curriculum?

During a security incident involving an insider threat, which TWO roles are most likely to be directly involved in the response?

During an incident investigation, a forensic analyst needs to preserve the integrity of a hard drive. Which two actions should the analyst take before imaging the drive?

A SOC analyst is investigating a possible insider threat. Which team member should be consulted due to the nature of the incident?

A financial institution is evaluating risk treatment options for a newly identified vulnerability in its online banking platform. The vulnerability has a high likelihood of exploitation but low business impact. Which risk treatment option is most appropriate?

Which TWO roles are typically responsible for making decisions regarding business impact and external communication during an incident? (Select two.)

A company is implementing threat intelligence sharing. Which THREE standards or platforms are used for this purpose? (Select three.)

During the Containment, Eradication, and Recovery phase, which TWO actions are typically performed? (Select two.)

A security analyst is reviewing the organization's security policies and procedures. The analyst must ensure that the policies align with the CIA triad. Which TWO of the following are primary goals of the CIA triad? (Choose two.)

A security manager is developing a business continuity plan (BCP) and needs to determine the maximum acceptable time that a critical business function can be unavailable after a disruption. Which metric should the manager use to define this time limit?

During a tabletop exercise, the CSIRT reviews its incident response plan and finds that no one has been designated to handle media inquiries, coordinate with legal, and communicate with customers. Which role in the incident response process is responsible for these activities?

A security analyst is reviewing the organization's incident response plan and notices that the plan does not address the handling of volatile evidence. The analyst wants to recommend procedures for collecting volatile data from a compromised Windows system before it is powered down. Which TWO types of data should be collected first because they are lost when the system is shut down? (Choose two.)

During which phase of the NIST SP 800-61 Rev 2 incident response process should an organization develop and exercise the incident response plan?

A security analyst receives an alert from the SIEM indicating a large number of failed login attempts from an external IP address targeting a user account. According to the incident response process, what should be the analyst's first action?

An organization's incident response team has identified a malware infection on a critical server. They need to collect evidence for potential legal action. Which of the following is the most important step to ensure the admissibility of the evidence?

Which role in the incident response process is primarily responsible for determining the business impact of an incident and making strategic decisions?

An employee is suspected of using company resources to access inappropriate websites. Which security policy most directly addresses this behavior?

During a risk assessment, a company identifies that the annualized loss expectancy (ALE) for a specific threat is $50,000. The cost to implement a mitigation control is $30,000 with an annual maintenance cost of $5,000. According to risk management principles, what is the most appropriate risk treatment option?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Security Policies and Procedures sessions

Start a Security Policies and Procedures only practice session

Every question in these sessions is drawn from the Security Policies and Procedures domain — nothing else.

Related practice questions

Related 200-201 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 200-201 exam test about Security Policies and Procedures?
Be able to place a scenario in the correct NIST SP 800-61 phase, pick containment that preserves volatile evidence, and describe forensic integrity steps. The single most important thing: never destroy volatile data before capturing it, and document chain of custody.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Policies and Procedures questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Policies and Procedures domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 200-201 topics?
Use the topic links above to move to related areas, or go back to the 200-201 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 200-201 exam covers. They are not copied from any real exam or dump site.