200-201 Security Policies and Procedures Practice Question
A security operations center (SOC) manager is developing a playbook for handling phishing incidents. The playbook must specify the first action an analyst should take upon receiving a reported phishing email. Which action should be performed first according to standard incident response procedures?
⚠ Common exam trap
The trap here is jumping to containment or remediation actions before validating the incident and gathering evidence, which can destroy critical information.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preserve the email and analyze its headers and attachments
Standard incident response procedures for phishing begin with preserving and analyzing the reported email to confirm maliciousness and extract indicators. This step enables accurate containment and remediation, such as blocking malicious domains and quarantining similar messages. Isolating, deleting, or notifying law enforcement are subsequent actions that depend on the initial analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify law enforcement about the phishing attempt
Why it's wrong here
Law enforcement notification may be required for certain incidents, but it is not the first action. The SOC must first validate the incident and gather enough information to determine if it meets reporting thresholds. Involving law enforcement prematurely without analysis could waste resources and fail to provide necessary details.
- ✗
Isolate the recipient's workstation from the network
Why it's wrong here
Isolating the workstation may be necessary if the user interacted with the email, but it is not the first action. The playbook should first preserve and analyze the email to determine if it is malicious and whether other users received it. Isolating prematurely could disrupt business operations without sufficient justification.
- ✓
Preserve the email and analyze its headers and attachments
Why this is correct
The first step in phishing response is to preserve the email as evidence and analyze its headers, URLs, and attachments to confirm malicious intent and identify indicators. This analysis informs subsequent actions such as blocking senders, quarantining similar emails, and notifying affected users. It aligns with standard incident response procedures that prioritize identification and containment planning.
- ✗
Delete the email from all mailboxes
Why it's wrong here
Deleting the email may be part of remediation, but doing so first destroys evidence and prevents analysis. The analyst needs to examine the email to determine its scope and indicators before removing it. Premature deletion could also miss other recipients who received the same message, leaving the organization exposed.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.