Courseiva
mediumMultiple Select

200-201 Practice Question: An incident response plan includes steps to…

An incident response plan includes steps to contain a ransomware outbreak. Which TWO actions are typically performed during the containment phase? (Select two.)

⚠ Common exam trap

Candidates often confuse containment with eradication, recovery, or post-incident activities — candidates often pick 'restore from backups' or 'notify law enforcement' because those sound urgent, but they belong to later phases.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disconnect infected systems from the network

Option D is correct because disconnecting infected systems from the network is a classic containment action that stops lateral movement and prevents the ransomware from spreading to additional hosts or shared resources. Option E is correct because quarantining malware samples isolates the malicious binaries in a controlled location so they cannot execute further while preserving them for forensic analysis and eradication planning. Option A is not a containment action; notifying law enforcement is typically an external communication or reporting step that occurs alongside or after containment. Option B is incorrect because identifying the initial infection vector is part of the investigation or root-cause analysis phase, not containment. Option C is incorrect because restoring data from backups is a recovery-phase activity performed after the threat has been contained and eradicated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Notify law enforcement

    Why it's wrong here

    Law enforcement notification is an escalation and communication activity, not a technical containment action that isolates affected systems. It tempts because ransomware is criminal activity and reporting feels obligatory, and it would be correct once containment is achieved and the organisation decides to pursue legal or regulatory reporting.

  • ✗

    Identify the initial infection vector

    Why it's wrong here

    Identifying the initial infection vector belongs to the identification or post-incident analysis phase, since it establishes root cause rather than halting spread. It tempts because scoping the entry point feels urgent during an outbreak, and it is genuinely the correct action when performing forensic root-cause investigation after containment has stopped propagation.

  • ✗

    Restore data from backups

    Why it's wrong here

    Restoring data from backups is eradication and recovery, performed only after the threat is removed and systems are clean. It tempts because backups are the definitive ransomware remedy, and it would be correct during the recovery phase once containment has stopped encryption and the environment is verified malware-free.

  • ✓

    Disconnect infected systems from the network

    Why this is correct

    Disconnecting infected systems from the network stops ransomware from spreading laterally to other hosts and shares, isolating the compromise while evidence is preserved. This is a classic containment action, distinct from eradication or recovery steps that follow once spread is halted.

  • ✓

    Quarantine the malware samples

    Why this is correct

    Quarantining malware samples preserves volatile evidence and prevents further execution or reinfection across the estate, directly satisfying the containment phase's requirement to halt the outbreak's spread. Isolating the artefacts supports later forensic analysis without allowing the ransomware binary to re-trigger encryption on other Microsoft Entra ID-joined endpoints.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.