Courseiva
hardMultiple ChoiceObjective-mapped

200-201 Practice Question: A large enterprise has a security policy that…

A large enterprise has a security policy that mandates data classification and strict access controls. An IT administrator, John, has been granted temporary administrative privileges to resolve a server issue. During the maintenance window, John accesses a file server and downloads a spreadsheet containing customer PII (Personally Identifiable Information) classified as 'Confidential'. John then emails the spreadsheet to his personal email account to work from home. The security team receives an alert from the DLP system indicating the email transmission. According to the company's incident response policy, which of the following is the FIRST action the security team should take?

⚠ Common exam trap

Cisco often tests the distinction between reactive containment (e.g., blocking/revoking) and the mandated first step of evidence preservation and incident initiation, causing candidates to confuse operational urgency with proper forensic procedure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Preserve evidence, isolate the affected systems, and initiate the incident response process

The correct first action is to preserve evidence, isolate affected systems, and initiate the incident response process. This aligns with NIST SP 800-61 and ISO 27035, which mandate that containment and evidence preservation precede any investigative or disciplinary steps. Jumping to revocation or interviews risks spoliation of logs, email metadata, and forensic artifacts critical to determining the scope of the data exfiltration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Block the email transmission and restore the file from backup

    Why it's wrong here

    Blocking and restoring are remediation steps that should follow evidence collection to avoid destroying evidence.

  • Revoke John's network access immediately and escalate to HR for disciplinary action

    Why it's wrong here

    While disciplinary action may be warranted, immediate revocation without preserving evidence could compromise forensic integrity.

  • Interview John to determine his intent and whether it was accidental

    Why it's wrong here

    Interviewing a suspect before securing evidence can lead to tampering or destruction of digital evidence.

  • Preserve evidence, isolate the affected systems, and initiate the incident response process

    Why this is correct

    This aligns with standard incident response procedures: first preserve evidence, then initiate the formal process.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.