TechNuggets Academy

Security Policies and Procedures

Free Cisco Certified CyberOps Associate practice — 6 questions on Security Policies and Procedures, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Security Policies and Procedures
During a breach investigation, an analyst compiles a list of C2 domains, hosting IP addresses, and DNS records the attacker used across multiple campaigns. Which Diamond Model feature is the analyst documenting?
Infrastructure represents the physical and logical means an attacker uses to deliver a capability and maintain communication with compromised systems, including domains, IPs, and hosting resources.
Question 2 of 6 · Security Policies and Procedures
A SOC completed eradication and recovery for a ransomware incident three weeks ago. The team now holds a meeting to document what worked, what failed, and to update detection signatures in the IR plan. According to the NIST 800-61 incident response lifecycle, which phase does this activity belong to?
NIST 800-61 explicitly classifies lessons-learned reviews and plan updates following incident closure as Post-Incident Activity; its outputs later feed back into future Preparation.
Question 3 of 6 · Security Policies and Procedures
An attacker crafts a malicious PDF and emails it to several employees disguised as an invoice attachment. No employee has opened the file yet. Which stage of the Cyber Kill Chain is currently in progress?
Delivery is the transmission of the weaponized payload to the target, which describes the email being sent but not yet opened.
Question 4 of 6 · Security Policies and Procedures
A hospital's patient portal is breached, exposing electronic medical records, diagnosis codes, and insurance claim numbers for 50,000 patients located in the United States. Which compliance framework primarily governs the organization's obligations for this incident?
HIPAA governs protection of PHI/ePHI for US healthcare entities, and medical records, diagnosis codes, and claims data are classic PHI covered directly under this framework.
Question 5 of 6 · Security Policies and Procedures
Which of the following is captured as part of a server profile rather than a network profile during security baseline monitoring?
A server profile documents host-specific attributes such as listening ports, logged-on users, running processes, and scheduled tasks for that particular system.
Question 6 of 6 · Security Policies and Procedures
A company's proprietary source code for a trading algorithm is exfiltrated by an insider. Which category of protected data best classifies this stolen information?
Proprietary source code and algorithms represent trade secrets and company creations, which are classified as Intellectual Property rather than data tied to an individual's identity.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →