Courseiva

200-201 Security Policies and Procedures Practice Question

A SOC manager is drafting the organization's incident response plan and wants to align it with the NIST SP 800-61 Rev. 2 lifecycle so that phases are clearly defined for auditors. Which sequence correctly represents the four phases of the incident response lifecycle as described in NIST SP 800-61 Rev. 2?

⚠ Common exam trap

The trap here is assuming the famous containment, eradication, and recovery steps are separate top-level phases rather than a single combined phase in the NIST SP 800-61 Rev. 2 lifecycle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Preparation; Detection and Analysis; Containment, Eradication, and Recovery; Post-Incident Activity

NIST SP 800-61 Rev. 2 organizes incident response into four phases: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity. A plan built on this structure gives clear entry and exit criteria for each phase, supports role assignment, and provides auditors with a recognizable mapping. The other sequences either describe only response sub-steps or borrow generic project management terms that do not match the standard.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Identification, Containment, Eradication, Recovery

    Why it's wrong here

    This sequence lists steps that belong inside the handling of an incident, not the four top-level NIST SP 800-61 Rev. 2 phases. Containment, eradication, and recovery are sub-activities of the response function, while identification is part of detection and analysis. Using this list as the lifecycle omits preparation and post-incident activity, so it would not satisfy an auditor mapping controls to the standard's actual structure.

  • ✗

    Preparation, Prevention, Detection, Response

    Why it's wrong here

    While prevention and response are security concepts, this is not the NIST SP 800-61 Rev. 2 incident response lifecycle. Prevention is generally treated as part of preparation and risk mitigation rather than a distinct phase, and the standard's second phase is named Detection and Analysis. Presenting this sequence to auditors would misrepresent the standard's terminology and could cause gaps in documenting analysis and post-incident review activities.

  • ✗

    Planning, Execution, Monitoring, Closure

    Why it's wrong here

    These terms describe a generic project management lifecycle, not the NIST SP 800-61 Rev. 2 incident response phases. Incident response requires preparation specific to handling incidents, detection and analysis of events, containment through recovery actions, and post-incident activity such as lessons learned. Using project management terminology would not demonstrate alignment with the standard and could confuse roles and deliverables during an actual incident.

  • ✓

    Preparation; Detection and Analysis; Containment, Eradication, and Recovery; Post-Incident Activity

    Why this is correct

    NIST SP 800-61 Rev. 2 defines exactly these four phases in this order, beginning with preparation before an incident occurs, then detection and analysis, then containment, eradication, and recovery, and finally post-incident activity. Adopting this structure gives the SOC manager a recognized framework that auditors can map to, and it ensures lessons learned feed back into preparation for continuous improvement.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.