200-201 • Practice Exam 53
Free 200-201 practice exam — 20 questions with explanations. Set 53. No signup required.
A security analyst is reviewing an incident response policy that requires the team to preserve evidence for potential legal action. The analyst notices that the policy does not address how to handle evidence when a compromised system must be rebooted to restore services. What should the analyst recommend to balance evidence preservation with operational recovery?
Choose an answer to begin — your selection is scored in the full session.
20 questions · instant feedback and full explanations after every question.