Security Policies and Procedures for Cisco CyberOps Associate (CBROPS 200-201)

This page covers the Security Policies and Procedures domain of the Cisco CyberOps Associate (CBROPS 200-201) certification. Master Cybersecurity offers 12 practice questions in this domain, drawn from the same content we use across our timed exam simulations. Below are five sample questions with full answer explanations.

Sample Practice Questions

  1. Question 1

    Which security principle requires more than one person is required to perform a critical task?
    1. A. least privilege
    2. B. need to know
    3. C. separation of duties
    4. D. due diligence
    Explanation

    The correct answer is: C. separation of duties.

    Separation of duties is the control that deliberately splits a critical task so that no single individual can complete it alone, which is why high risk actions such as approving a large payment, releasing code to production or destroying evidence-grade media are built to require two people; the aim is to make fraud or one careless mistake require collusion rather than a single decision. Least privilege is a related but distinct idea: each account or process is granted only the permissions its role genuinely needs, which limits blast radius rather than demanding a second participant. Need to know restricts access to specific information based on whether a person duties actually require that data, and is usually paired with clearance levels in classified environments. Due diligence is a governance obligation to keep verifying that controls, suppliers and processes remain adequate over time, an assurance activity rather than a dual control requirement. Only separation of duties mandates the second person.

  2. Question 2

    How is attacking a vulnerability categorized?
    1. A. action on objectives
    2. B. delivery
    3. C. exploitation
    4. D. installation
    Explanation

    The correct answer is: C. exploitation.

    Attacking a vulnerability, meaning the moment a weakness in software or configuration is actually triggered to obtain code execution or unauthorised access, is categorised as exploitation in the Cyber Kill Chain. It is the hinge of the model: every earlier stage prepares and transmits the attack, and every later stage depends on the access that exploitation produces. Actions on objectives is the final stage, where the adversary does what the intrusion was for, exfiltrating data, encrypting systems, tampering with records or expanding laterally. Delivery immediately precedes exploitation and covers transmitting the weaponised payload to the target through email, a web request, removable media or an exposed service, at which point the payload has still not run. Installation follows exploitation and concerns persistence, dropping a backdoor, webshell, service or scheduled task so access survives a reboot or a patch. Only exploitation names the act of abusing the flaw itself.

  3. Question 3

    Which principle is being followed when an analyst gathers information relevant to a security incident to determine the appropriate course of action?
    1. A. decision making
    2. B. rapid response
    3. C. data mining
    4. D. due diligence
    Explanation

    The correct answer is: A. decision making.

    Collecting the facts that surround an incident so that a defensible choice can be made is the decision making principle at work: the analyst pulls alert detail, log context, asset value and scope together, weighs the possible responses, and only then selects a containment or escalation path, which is exactly how SOC triage and playbooks are structured. Rapid response describes the speed at which action is taken once a course has been chosen, not the deliberate gathering and weighing of evidence that must precede it, and acting without that groundwork is how analysts break production systems or destroy evidence. Data mining is an analytic technique for discovering patterns and correlations inside large data sets; it can feed an investigation, but it is a method rather than the principle governing how a response is selected. Due diligence is the ongoing organisational obligation to keep verifying that controls, suppliers and processes remain adequate, a governance duty rather than the act of evaluating one incident to pick the right next step.

  4. Question 4

    A security specialist notices 100 HTTP GET and POST requests for multiple pages on the web servers. The agent in the requests contains PHP code that, if executed, creates and writes to a new PHP file on the webserver. Which event category is described?
    1. A. reconnaissance
    2. B. action on objectives
    3. C. installation
    4. D. exploitation
    Explanation

    The correct answer is: C. installation.

    A request whose agent field carries PHP that, if executed, writes a brand new PHP file onto the web server is an attempt to plant a webshell, and dropping persistent attacker-controlled code onto a compromised host is the installation stage of the Cyber Kill Chain. Installation is defined as establishing a foothold that outlives the initial intrusion, and a server-side script the adversary can call back to later is the classic example. Reconnaissance is the earlier research and scanning stage where hosts, pages and technologies are enumerated, which the request volume only hints at. Actions on objectives is the final stage, where the foothold is used to steal, encrypt or destroy data or to move deeper into the network, none of which is described here. Exploitation is the instant a vulnerability is triggered to obtain code execution; the meaningful observation in this activity is the persistent file being created on disk, which categorises the event as installation rather than as the trigger that preceded it.

  5. Question 5

    During which phase of the forensic process is data that is related to a specific event labeled and recorded to preserve its integrity?
    1. A. examination
    2. B. investigation
    3. C. collection
    4. D. reporting
    Explanation

    The correct answer is: C. collection.

    Collection is the forensic phase in which data tied to a specific event is identified, labelled, hashed and recorded so its integrity can be demonstrated later; this is where evidence tags, photographs, hash values and the first chain of custody entries are created, and where order of volatility decides what is captured first, from registers and memory through network state and running processes to disk and remote logs. Examination follows and applies tools and techniques to the acquired copy in order to surface relevant material, filtering, carving and extracting artifacts without touching the original. Investigation is loose umbrella language for the overall effort rather than a named phase, so it cannot be the step that describes labelling and recording. Reporting is the final phase, where findings, methods and conclusions are documented for management, counsel or a court. Integrity must be locked in at the moment evidence is acquired, which is why labelling and recording belong to collection.

Other Cisco CyberOps Associate (CBROPS 200-201) domains

Practice all 12 Security Policies and Procedures questions · Browse Cisco CyberOps Associate (CBROPS 200-201)