mediumMultiple Select
200-201 Practice Question: An incident response plan includes steps to…
An incident response plan includes steps to contain a ransomware outbreak. Which TWO actions are typically performed during the containment phase? (Select two.)
⚠ Common exam trap
Candidates often confuse containment with eradication, recovery, or post-incident activities — candidates often pick 'restore from backups' or 'notify law enforcement' because those sound urgent, but they belong to later phases.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect infected systems from the network
Option D is correct because disconnecting infected systems from the network is a classic containment action that stops lateral movement and prevents the ransomware from spreading to additional hosts or shared resources. Option E is correct because quarantining malware samples isolates the malicious binaries in a controlled location so they cannot execute further while preserving them for forensic analysis and eradication planning. Option A is not a containment action; notifying law enforcement is typically an external communication or reporting step that occurs alongside or after containment. Option B is incorrect because identifying the initial infection vector is part of the investigation or root-cause analysis phase, not containment. Option C is incorrect because restoring data from backups is a recovery-phase activity performed after the threat has been contained and eradicated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify law enforcement
Why it's wrong here
Law enforcement notification is an escalation and communication activity, not a technical containment action that isolates affected systems. It tempts because ransomware is criminal activity and reporting feels obligatory, and it would be correct once containment is achieved and the organisation decides to pursue legal or regulatory reporting.
- ✗
Identify the initial infection vector
Why it's wrong here
Identifying the initial infection vector belongs to the identification or post-incident analysis phase, since it establishes root cause rather than halting spread. It tempts because scoping the entry point feels urgent during an outbreak, and it is genuinely the correct action when performing forensic root-cause investigation after containment has stopped propagation.
- ✗
Restore data from backups
Why it's wrong here
Restoring data from backups is eradication and recovery, performed only after the threat is removed and systems are clean. It tempts because backups are the definitive ransomware remedy, and it would be correct during the recovery phase once containment has stopped encryption and the environment is verified malware-free.
- ✓
Disconnect infected systems from the network
Why this is correct
Disconnecting infected systems from the network stops ransomware from spreading laterally to other hosts and shares, isolating the compromise while evidence is preserved. This is a classic containment action, distinct from eradication or recovery steps that follow once spread is halted.
- ✓
Quarantine the malware samples
Why this is correct
Quarantining malware samples preserves volatile evidence and prevents further execution or reinfection across the estate, directly satisfying the containment phase's requirement to halt the outbreak's spread. Isolating the artefacts supports later forensic analysis without allowing the ransomware binary to re-trigger encryption on other Microsoft Entra ID-joined endpoints.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.