200-201 Security Policies and Procedures Practice Question
During the Containment, Eradication, and Recovery phase, the incident response team collects evidence from a compromised system. Which document is used to record the chain of custody?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Chain of custody form
Chain of custody documentation tracks who handled evidence from collection to court presentation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data classification policy
Why it's wrong here
A data classification policy assigns sensitivity labels and handling rules to information assets; it contains no fields for recording evidence transfers, timestamps or signatures. It is tempting because it governs how evidence should be stored and shared, so it would be the correct document when determining the handling requirements for the collected evidence itself.
- ✗
Acceptable Use Policy
Why it's wrong here
An acceptable use policy defines how employees may use organisational systems and data; it records no custodian names, transfer dates or signatures. It is tempting because evidence handling involves staff conduct, so an AUP would be the right document when addressing whether an employee's system usage breached organisational rules.
- ✗
Incident response plan
Why it's wrong here
The incident response plan defines phases, roles and escalation procedures for handling incidents; it does not capture individual evidence transfers with signatures and timestamps. It is tempting because evidence collection occurs within the Containment, Eradication and Recovery phase it describes, so it would be correct when determining the team's procedural steps during that phase.
- ✓
Chain of custody form
Why this is correct
The chain of custody form records each transfer, handler, timestamp and storage location of evidence. Completing it during collection creates the auditable trail proving the evidence was never tampered with, which is required for it to be admissible.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.