Courseiva

200-201 Security Policies and Procedures Practice Question

A security analyst is reviewing the organization's incident response plan. The plan defines several roles, including one responsible for coordinating all incident response activities and serving as the central point of communication. During a recent ransomware incident, this person was responsible for declaring the incident and ensuring that all stakeholders were informed. Which role does this describe?

⚠ Common exam trap

Many candidates confuse the Incident Response Manager with the Incident Handler, assuming the person doing the technical work is also the one coordinating the entire response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident Response Manager

The Incident Response Manager is responsible for the overall coordination of the incident response process. This includes declaring incidents, managing communication with stakeholders, and ensuring that the response follows the organization's policies. The other roles have more specific or tactical responsibilities that do not include overarching coordination.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Legal Advisor

    Why it's wrong here

    The Legal Advisor provides guidance on legal and regulatory requirements during an incident but does not coordinate the overall response or declare incidents. The scenario emphasizes central coordination and stakeholder communication, which are not primary duties of the Legal Advisor.

  • ✗

    SOC Tier 1 Analyst

    Why it's wrong here

    A SOC Tier 1 Analyst monitors alerts and performs initial triage. This role does not have the authority to declare incidents or coordinate high-level communication. In the scenario, the responsibilities are strategic and managerial, not entry-level monitoring, so this role is incorrect.

  • ✗

    Incident Handler

    Why it's wrong here

    The Incident Handler is responsible for the tactical response, such as analyzing malware and containing the threat. This role does not typically declare incidents or coordinate all communication with stakeholders. In this scenario, the person described is performing strategic coordination, which is beyond the Incident Handler's tactical duties.

  • ✓

    Incident Response Manager

    Why this is correct

    The Incident Response Manager leads the incident response process, declares incidents, and coordinates communication among stakeholders. This role aligns with the scenario's description of declaring the incident and ensuring all stakeholders are informed. It is distinct from the tactical Incident Handler role.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.