Courseiva

200-201 Security Policies and Procedures Practice Question

During an incident investigation, the IR team collects evidence from a compromised server. The evidence must be admissible in court. Which documentation is essential to maintain the chain of custody?

⚠ Common exam trap

200-201 often tests the misconception that technical details like CVSS scores or policies are part of chain of custody, when the essential element is the access log.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A log of who accessed the evidence and when

Chain of custody documentation must include a log of who accessed the evidence, when, and for what purpose, to ensure integrity and admissibility in court. This log creates an auditable trail that proves the evidence has not been tampered with. Without it, the evidence may be deemed inadmissible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A log of who accessed the evidence and when

    Why this is correct

    A chain-of-custody log records every individual who handled, transferred or accessed the evidence, with timestamps and signatures. This continuous audit trail satisfies the admissibility constraint by proving the evidence was never tampered with between seizure and courtroom presentation.

  • ✗

    The CVSS score of the vulnerability

    Why it's wrong here

    A CVSS score rates vulnerability severity; it records nothing about who handled the evidence. Chain of custody demands a form logging each transfer, timestamp and signature. CVSS is tempting because it documents the incident technically, but it cannot prove evidence integrity in court.

  • ✗

    A copy of the incident response plan

    Why it's wrong here

    The incident response plan describes procedures, not the custody record itself. Admissibility requires a chain-of-custody form documenting every transfer, time and handler. The plan is tempting because it governs the investigation, yet it evidences no continuous control of the specific seized evidence.

  • ✗

    The organization's acceptable use policy

    Why it's wrong here

    An acceptable use policy states employee obligations, not evidence handling. Chain of custody requires a form logging each transfer: who held the evidence, when, and why. The policy is tempting because it is a governance document, but it records no custody events for court admissibility.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.