200-201 Security Policies and Procedures Practice Question
During an incident investigation, the IR team collects evidence from a compromised server. The evidence must be admissible in court. Which documentation is essential to maintain the chain of custody?
⚠ Common exam trap
200-201 often tests the misconception that technical details like CVSS scores or policies are part of chain of custody, when the essential element is the access log.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A log of who accessed the evidence and when
Chain of custody documentation must include a log of who accessed the evidence, when, and for what purpose, to ensure integrity and admissibility in court. This log creates an auditable trail that proves the evidence has not been tampered with. Without it, the evidence may be deemed inadmissible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A log of who accessed the evidence and when
Why this is correct
A chain-of-custody log records every individual who handled, transferred or accessed the evidence, with timestamps and signatures. This continuous audit trail satisfies the admissibility constraint by proving the evidence was never tampered with between seizure and courtroom presentation.
- ✗
The CVSS score of the vulnerability
Why it's wrong here
A CVSS score rates vulnerability severity; it records nothing about who handled the evidence. Chain of custody demands a form logging each transfer, timestamp and signature. CVSS is tempting because it documents the incident technically, but it cannot prove evidence integrity in court.
- ✗
A copy of the incident response plan
Why it's wrong here
The incident response plan describes procedures, not the custody record itself. Admissibility requires a chain-of-custody form documenting every transfer, time and handler. The plan is tempting because it governs the investigation, yet it evidences no continuous control of the specific seized evidence.
- ✗
The organization's acceptable use policy
Why it's wrong here
An acceptable use policy states employee obligations, not evidence handling. Chain of custody requires a form logging each transfer: who held the evidence, when, and why. The policy is tempting because it is a governance document, but it records no custody events for court admissibility.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.