Courseiva
mediumMultiple Choice

200-201 Practice Question: An incident response plan specifies that…

An incident response plan specifies that containment must be completed before eradication. A security analyst identifies a malware infection on a critical server. What should be done first?

⚠ Common exam trap

Cisco often tests the strict ordering of the incident response phases (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident Activity), and the trap here is that candidates confuse eradication actions (like running antivirus or reinstalling the OS) with the required first containment step, leading them to choose a technically plausible but procedurally incorrect answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disconnect the server from the network

According to the incident response plan, containment must be completed before eradication. Disconnecting the server from the network (Option A) is the immediate containment action that prevents the malware from spreading laterally to other hosts, preserving the integrity of the network and allowing for forensic analysis. This step aligns with the NIST SP 800-61 incident response lifecycle, where containment is prioritized to limit damage before any eradication or recovery steps are taken.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Disconnect the server from the network

    Why this is correct

    Containment precedes eradication per the plan, and disconnecting the server from the network isolates the malware, preventing lateral spread or data exfiltration. This is the containment step, satisfying the stem's ordering requirement before any eradication or recovery actions begin.

  • ✗

    Run antivirus scans

    Why it's wrong here

    Antivirus scans are eradication, not containment, so running them first breaches the plan's ordering and may let malware spread or destroy volatile evidence. Scanning is tempting because it is the habitual first reflex on an infected host, and it would be right once the server is isolated and the threat is no longer propagating.

  • ✗

    Notify law enforcement

    Why it's wrong here

    Notification is an external communication step, not containment; the plan requires isolating the infected server first to halt malware spread before eradication. It tempts because law enforcement involvement matters for legal and evidentiary reasons, but that occurs alongside or after containment, never before it.

  • ✗

    Reinstall the operating system

    Why it's wrong here

    Reinstalling the OS is a destructive eradication and recovery step; it wipes volatile memory and logs before containment, destroying evidence and leaving the infection's source untouched. It is tempting as a guaranteed clean rebuild, and would be correct after containment and eradication, once forensic data is preserved.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.