Skip to content

210-250 Practice Questions

Prepare for 210-250 with more than an answer.

220 questions in the full set17 sample questionsUpdated Jan 23, 2026

Unlock the full exam and previous versions

  • v1Standard 313 questions Locked
  • 210-250Legacy Cyber Ops Understanding Cisco Cybersecurity Fundamentals (SECFND) 220 questions Current
  • 210-255Legacy Implementing Cisco Cybersecurity Operations (SECOPS) 207 questions Locked
Exam fee
$300 USD
Level
Associate
Valid for
3 years
Domains covered on the exam 6
  1. Network Concepts12%
  2. Security Concepts17%
  3. Cryptography12%
  4. Host-Based Analysis19%
  5. Security Monitoring19%
  6. Attack Methods21%
  1. 1

    Scenario: A company is updating its risk management strategy. They have identified a legacy server that cannot be patched. The cost to replace it is $50,000. The server contains public data with low sensitivity. The likelihood of compromise is estimated at once every 10 years, with a recovery cost of $5,000. The company decides to take no action and document the potential loss.

    Which risk response strategy has the company adopted?

    Show answer details

    Correct answer: A

    Risk Acceptance occurs when an organization identifies a risk but decides not to take any action to reduce it, usually because the cost of mitigation exceeds the potential loss. In this case, spending $50k to prevent a $5k loss is not cost-effective.

  2. 2

    The Common Vulnerability Scoring System (CVSS) is used to assess the severity of security vulnerabilities. Which metric group represents the intrinsic characteristics of a vulnerability that are constant over time and across user environments?

    Show answer details

    Correct answer: D

    The Base Metric Group represents the intrinsic qualities of a vulnerability that are constant over time and user environments. It includes Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope, Confidentiality, Integrity, and Availability.

  3. 3

    Which TWO statements correctly describe the principle of Defense-in-Depth? (Select TWO)

    Show answer details

    Correct answer: B, C

    Defense-in-Depth covers all domains of security, not just technical controls.

    Defense-in-Depth relies on layering security controls (physical, technical, administrative) so that a failure in one layer does not compromise the entire asset.

  4. 4

    Which regulatory standard applies specifically to the protection of credit card data and requires merchants to implement secure network architectures?

    Show answer details

    Correct answer: D

    PCI-DSS (Payment Card Industry Data Security Standard) mandates security controls for organizations that handle branded credit cards.

  5. 5

    True or False: In a discretionary access control (DAC) model, the system administrator is the only one who can determine access permissions for a file.

    Show answer details

    Correct answer: B

    False. In DAC (Discretionary Access Control), the data owner (usually the creator of the file) has the discretion to grant or restrict access to others.

  6. 6

    Which definition of a fork in Linux is true? A.daemon to execute scheduled commandsB.parentdirectory name of a file path nameC.macros for manipulating CPU setsD.new process created by a parent process

    Show answer details

    Correct answer: D

  7. 7

    Which identifier is used to describe the application or process that submitted a log message? A.actionB.selectorC.priorityD.facility

    Show answer details

    Correct answer: D

  8. 8

    Which protocol is expected to have a user agent, host, and referrer header in a packet capture? A.NTPB.HTTPC.DNSD.SSH

    Show answer details

    Correct answer: B

Create an account to continue.