Courseiva
hardMultiple ChoiceObjective-mapped

200-201 Practice Question: A financial services company has a security…

A financial services company has a security policy that all remote access must be through VPN with two-factor authentication. An employee on a business trip uses a hotel Wi-Fi to connect to the corporate network but claims the VPN client was not working, so they used RDP directly over the internet to access their desktop. The employee's manager approved this as a temporary measure. The security team discovers this during a log review. The policy has no provision for temporary exceptions. What should be the security team's first action?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Investigate whether any data was compromised during the session.

The security team's first action should be to investigate whether any data was compromised during the unauthorized RDP session. This aligns with incident response procedures to first assess the scope and impact before taking other actions like reporting or blocking. Option B is premature without understanding the impact; Option C is a broader action that may be needed later but not first; Option D is incorrect because the manager's approval does not override the security policy, which has no provision for temporary exceptions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Investigate whether any data was compromised during the session.

    Why this is correct

    Understanding the risk helps guide subsequent actions appropriately.

  • Report the violation to the security officer and recommend disciplinary action.

    Why it's wrong here

    Reporting is important, but assessing compromise should come first.

  • Disable RDP access from the internet for all users immediately.

    Why it's wrong here

    This could be a later step, but first understand the risk and impact.

  • Accept the manager's approval as sufficient authorization.

    Why it's wrong here

    The policy dictates that no exceptions without formal process; manager approval is not enough.

About these practice questions

Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.