hardMultiple ChoiceObjective-mapped
200-201 Practice Question: A large enterprise has a security policy that…
A large enterprise has a security policy that mandates data classification and strict access controls. An IT administrator, John, has been granted temporary administrative privileges to resolve a server issue. During the maintenance window, John accesses a file server and downloads a spreadsheet containing customer PII (Personally Identifiable Information) classified as 'Confidential'. John then emails the spreadsheet to his personal email account to work from home. The security team receives an alert from the DLP system indicating the email transmission. According to the company's incident response policy, which of the following is the FIRST action the security team should take?
⚠ Common exam trap
Cisco often tests the distinction between reactive containment (e.g., blocking/revoking) and the mandated first step of evidence preservation and incident initiation, causing candidates to confuse operational urgency with proper forensic procedure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preserve evidence, isolate the affected systems, and initiate the incident response process
The correct first action is to preserve evidence, isolate affected systems, and initiate the incident response process. This aligns with NIST SP 800-61 and ISO 27035, which mandate that containment and evidence preservation precede any investigative or disciplinary steps. Jumping to revocation or interviews risks spoliation of logs, email metadata, and forensic artifacts critical to determining the scope of the data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block the email transmission and restore the file from backup
Why it's wrong here
Blocking and restoring are remediation steps that should follow evidence collection to avoid destroying evidence.
- ✗
Revoke John's network access immediately and escalate to HR for disciplinary action
Why it's wrong here
While disciplinary action may be warranted, immediate revocation without preserving evidence could compromise forensic integrity.
- ✗
Interview John to determine his intent and whether it was accidental
Why it's wrong here
Interviewing a suspect before securing evidence can lead to tampering or destruction of digital evidence.
- ✓
Preserve evidence, isolate the affected systems, and initiate the incident response process
Why this is correct
This aligns with standard incident response procedures: first preserve evidence, then initiate the formal process.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.