200-201 Security Concepts Practice Question
A security analyst is investigating a recent security incident and needs to determine the extent of the compromise. The analyst wants to understand which systems were affected and what data may have been accessed. Which phase of the incident response process is the analyst currently performing?
⚠ Common exam trap
The trap here is thinking that any investigative activity belongs to containment, when scope determination is specifically part of detection and analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detection and analysis
The detection and analysis phase of incident response involves validating incidents, determining their scope, and identifying affected systems and data. The analyst's investigation into which systems were compromised and what data was accessed is a textbook example of this phase, which must be completed before containment and eradication can be effectively planned.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Detection and analysis
Why this is correct
Detection and analysis is the phase where analysts validate whether an incident occurred, determine its scope, and identify affected systems and data. The analyst's goal of understanding which systems were compromised and what data was accessed aligns directly with this phase. This step precedes containment and eradication and is critical for making informed decisions about subsequent response actions.
- ✗
Post-incident activity
Why it's wrong here
Post-incident activity occurs after the incident has been resolved and focuses on lessons learned, reporting, and improving future response. The analyst is actively investigating an ongoing incident, not reviewing a completed one. Confusing this phase with the current work would mean overlooking the immediate need to assess scope and could leave the organization vulnerable to further damage.
- ✗
Preparation
Why it's wrong here
Preparation involves establishing incident response capabilities, tools, and training before an incident occurs. It does not include investigating an active incident to determine scope. In this scenario, the analyst is already responding to a security event, so the preparation phase has passed. Choosing preparation would indicate a misunderstanding of the sequential phases of incident response and could delay containment efforts.
- ✗
Containment, eradication, and recovery
Why it's wrong here
Containment, eradication, and recovery involves limiting the damage, removing the threat, and restoring systems to normal operation. While these actions follow analysis, the analyst in this scenario is still determining the extent of the compromise, not yet taking action to contain or remove it. Selecting this phase would skip the necessary investigative work that informs effective containment strategies.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.