210-250 Practice Questions
Prepare for 210-250 with more than an answer.
Unlock the full exam and previous versions
- v1Standard 313 questions Locked
- 210-250Legacy Cyber Ops Understanding Cisco Cybersecurity Fundamentals (SECFND) 220 questions Current
- 210-255Legacy Implementing Cisco Cybersecurity Operations (SECOPS) 207 questions Locked
- Exam fee
- $300 USD
- Level
- Associate
- Valid for
- 3 years
Domains covered on the exam 6
- Network Concepts12%
- Security Concepts17%
- Cryptography12%
- Host-Based Analysis19%
- Security Monitoring19%
- Attack Methods21%
- 1
Scenario: A company is updating its risk management strategy. They have identified a legacy server that cannot be patched. The cost to replace it is $50,000. The server contains public data with low sensitivity. The likelihood of compromise is estimated at once every 10 years, with a recovery cost of $5,000. The company decides to take no action and document the potential loss.
Which risk response strategy has the company adopted?
Show answer details
Correct answer: A
Risk Acceptance occurs when an organization identifies a risk but decides not to take any action to reduce it, usually because the cost of mitigation exceeds the potential loss. In this case, spending $50k to prevent a $5k loss is not cost-effective.
- 2
The Common Vulnerability Scoring System (CVSS) is used to assess the severity of security vulnerabilities. Which metric group represents the intrinsic characteristics of a vulnerability that are constant over time and across user environments?
Show answer details
Correct answer: D
The Base Metric Group represents the intrinsic qualities of a vulnerability that are constant over time and user environments. It includes Attack Vector, Attack Complexity, Privileges Required, User Interaction, Scope, Confidentiality, Integrity, and Availability.
- 3
Which TWO statements correctly describe the principle of Defense-in-Depth? (Select TWO)
Show answer details
Correct answer: B, C
Defense-in-Depth covers all domains of security, not just technical controls.
Defense-in-Depth relies on layering security controls (physical, technical, administrative) so that a failure in one layer does not compromise the entire asset.
- 4
Which regulatory standard applies specifically to the protection of credit card data and requires merchants to implement secure network architectures?
Show answer details
Correct answer: D
PCI-DSS (Payment Card Industry Data Security Standard) mandates security controls for organizations that handle branded credit cards.
- 5
True or False: In a discretionary access control (DAC) model, the system administrator is the only one who can determine access permissions for a file.
Show answer details
Correct answer: B
False. In DAC (Discretionary Access Control), the data owner (usually the creator of the file) has the discretion to grant or restrict access to others.
- 6
Which definition of a fork in Linux is true? A.daemon to execute scheduled commandsB.parentdirectory name of a file path nameC.macros for manipulating CPU setsD.new process created by a parent process
Show answer details
Correct answer: D
- 7
Which identifier is used to describe the application or process that submitted a log message? A.actionB.selectorC.priorityD.facility
Show answer details
Correct answer: D
- 8
Which protocol is expected to have a user agent, host, and referrer header in a packet capture? A.NTPB.HTTPC.DNSD.SSH
Show answer details
Correct answer: B
