Courseiva

200-201 Security Policies and Procedures Practice Question

A SOC Tier 2 analyst is investigating an alert that was escalated from Tier 1. The analyst suspects the malware is using a new variant of ransomware. What is the most appropriate next step for the Tier 2 analyst?

⚠ Common exam trap

The trap is jumping to containment or escalation before completing Tier 2 analysis — the exam expects the analyst to investigate and correlate first, not delete files or skip to Tier 3.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform malware analysis and correlate with other alerts

A Tier 2 analyst's role is to perform deeper investigation than Tier 1, including malware analysis and correlating the alert with other telemetry to determine scope and impact. Performing malware analysis and correlating with other alerts is the appropriate next step to confirm whether the ransomware is a new variant and to understand its behavior. This informs containment and escalation decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Notify legal counsel immediately

    Why it's wrong here

    Legal counsel is engaged once a breach is confirmed and notification obligations arise, not during initial technical triage of a suspected variant. Early legal involvement is tempting given ransomware's regulatory implications, but the analyst must first perform technical analysis to establish scope and confirm the variant.

  • ✗

    Escalate directly to Tier 3 for advanced analysis

    Why it's wrong here

    Tier 3 handles deep reverse engineering and tooling, but Tier 2's role is to perform its own investigation and containment before further escalation. Passing the alert upward is tempting because a new variant sounds advanced, yet Tier 2 must first gather evidence and scope the incident.

  • ✓

    Perform malware analysis and correlate with other alerts

    Why this is correct

    Malware analysis identifies the ransomware variant's behaviour, indicators, and capabilities, while correlating with other alerts reveals infection scope and lateral movement. This combination is the appropriate Tier 2 next step before escalation, satisfying the need to characterise a suspected new ransomware variant.

  • ✗

    Delete the affected files to contain the spread

    Why it's wrong here

    Deleting files destroys volatile evidence and may trigger further encryption, and it does not stop a running process. Containment via deletion is tempting because it appears to halt spread quickly, but proper isolation preserves forensic artefacts while the new ransomware variant is analysed.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.