Courseiva
easyMultiple Choice

200-201 Practice Question: An organization's security policy requires that…

An organization's security policy requires that all security incidents be reported within one hour of discovery. A junior analyst notices an unauthorized login attempt but is unsure if it qualifies as an incident. What should the analyst do first?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Report the suspicious activity immediately

Reporting suspicious activity immediately aligns with the policy, even if not confirmed. Waiting or deleting logs could violate reporting requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete the logs to avoid false alarms

    Why it's wrong here

    Deleting logs destroys the evidence needed to investigate the unauthorised login attempt and breaches the reporting policy outright. It is tempting only as a misguided way to suppress false alarms, but log retention is required for incident response; the analyst must report the suspected incident and preserve all associated evidence intact.

  • ✗

    Wait until the incident is confirmed

    Why it's wrong here

    Waiting for confirmation delays reporting past the one-hour policy window, and the analyst lacks the authority to make that determination alone. It is tempting because confirming an incident before escalation avoids false alarms, but the policy requires reporting suspected incidents immediately; triage and confirmation belong to the incident response team, not the discovering analyst.

  • ✗

    Investigate on their own without reporting

    Why it's wrong here

    Investigating alone consumes the one-hour reporting window and withholds the unauthorised login attempt from the response team. It is tempting because gathering evidence before escalating appears diligent, but the policy mandates prompt reporting of suspected incidents; independent investigation is appropriate only after the incident has been reported and assigned.

  • ✓

    Report the suspicious activity immediately

    Why this is correct

    The one-hour reporting mandate applies from discovery, and uncertainty about classification does not justify delay. Reporting the suspicious activity immediately lets the security team triage whether it qualifies as an incident, satisfying the policy's timeframe while preserving evidence and enabling containment.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.