200-201 Security Policies and Procedures Practice Question
During a security incident, the incident handler identifies that the breach involves personally identifiable information (PII) of customers. Which role is primarily responsible for determining if legal notification requirements apply?
⚠ Common exam trap
It's easy for candidates to confuse the technical incident response role with the legal compliance role; candidates might assume the incident handler or CISO determines notification requirements, but legal counsel is the correct authority.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Legal counsel
Legal counsel is primarily responsible for interpreting breach notification laws (e.g., GDPR, CCPA, HIPAA) and determining whether the incident triggers mandatory legal notifications. They assess factors such as the type of data involved, the number of affected individuals, and the jurisdiction to decide if notification is required. The incident handler focuses on technical containment and recovery, not legal analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Legal counsel
Why this is correct
Legal counsel determines whether legal notification requirements apply, as they interpret breach-notification statutes and regulations governing PII. This satisfies the scenario's constraint: assessing statutory obligations after a PII breach. Security analysts and incident handlers identify and contain the incident, but only legal counsel can judge mandatory disclosure duties to customers, regulators, or authorities.
- ✗
Incident handler
Why it's wrong here
The incident handler investigates and contains the breach but does not own regulatory or contractual notification decisions; legal counsel or the privacy officer interprets breach-notification statutes. The handler's role is technical response and evidence gathering, and would be the correct answer if the question asked who performs containment or forensic analysis.
- ✗
HR
Why it's wrong here
HR manages employee relations and internal policy, not customer PII breach obligations; notification duties flow from privacy statutes and contracts, which HR lacks the authority or expertise to interpret. HR is tempting because it handles internal data-protection matters and staff communications, making it the right owner when the breached records belong to employees rather than customers.
- ✗
CISO
Why it's wrong here
The CISO owns security strategy and risk posture, not the legal analysis of whether notification statutes are triggered; that determination requires interpreting breach-notification law against the data involved, which is counsel's remit. The CISO is tempting because they lead incident response and sign off remediation, and would be the right escalation point for resourcing or risk acceptance decisions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.