200-201 Security Policies and Procedures Practice Question
A SOC Tier 2 analyst is investigating an alert that was escalated by Tier 1. The analyst needs to perform deeper correlation and malware analysis. Which of the following actions is most appropriate for Tier 2?
⚠ Common exam trap
It's easy for candidates to confuse the responsibilities of different SOC tiers, particularly assuming that proactive tasks like threat hunting or detection engineering are part of Tier 2's reactive investigation role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyze the malware sample in a sandbox and correlate with other indicators.
Tier 2 analysts are responsible for deeper investigation, including malware analysis and correlating indicators across multiple data sources. Analyzing a malware sample in a sandbox allows safe execution and observation of behavior, while correlation with other indicators (e.g., IOCs from other alerts) helps determine scope and impact. This aligns with the escalation from Tier 1, which typically handles initial triage. Options B and C are more advanced or proactive tasks often handled by Tier 3 or threat hunting teams, and D is a Tier 1 responsibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Analyze the malware sample in a sandbox and correlate with other indicators.
Why this is correct
Sandbox detonation executes the sample in an isolated environment, revealing runtime behaviour such as command-and-control callbacks, dropped files and registry persistence that static inspection misses. Correlating those artefacts with other indicators satisfies the Tier 2 requirement for deeper malware analysis and cross-event correlation, exceeding Tier 1 triage scope.
- ✗
Conduct threat hunting to proactively search for threats.
Why it's wrong here
Threat hunting is a proactive, hypothesis-driven search across the estate for undetected adversaries, not the reactive deepening of an already-escalated alert. It is tempting because Tier 2 staff possess the skills, but hunting is the correct choice when no alert exists and the team seeks unknown threats.
- ✗
Develop new detection rules for the SIEM.
Why it's wrong here
Detection engineering changes SIEM logic for future events and produces no findings about the current incident, leaving the escalated alert unanalysed. It is tempting because Tier 2 understands attacker behaviour, but rule authoring is the correct choice during detection-gap remediation, not while correlating an active alert.
- ✗
Perform initial triage and basic investigation.
Why it's wrong here
Initial triage and basic investigation belong to Tier 1, which already escalated this alert; repeating that work leaves the deeper correlation and malware analysis undone. It is tempting because triage feels like investigation, but it is the correct choice only for first-line alert validation and enrichment before escalation.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.