Courseiva
hardMultiple ChoiceObjective-mapped

200-201 GreenTech Inc Practice Question

GreenTech Inc. is a mid-sized company with 500 employees. The company uses Microsoft Exchange Online for email and has implemented a security policy that requires all employees to report suspicious emails to the security team. The security team uses a phishing simulation tool to train employees. In the past month, several employees have reported receiving emails that appear to be from the CEO requesting urgent wire transfers. The security team has blocked the sender domains and updated the email filters. However, one employee fell for the latest scam and transferred $50,000 to an account before reporting it. The security incident response plan states that any monetary loss must be reported to the board within 24 hours. The security analyst receives the report on Monday morning. What should the analyst do first based on the policy and best practices?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Immediately contact the bank to attempt to reverse the wire transfer

The immediate priority is to attempt to recover the funds. Contacting the bank to reverse the wire transfer should be the first step because there is a chance to stop or reverse the transaction if done promptly. Notifying the board (C) is required within 24 hours but is secondary to attempting recovery. A full forensic investigation (B) can be launched later, but it does not prevent monetary loss. Disabling email access (A) is overly disruptive and not the first action; it may be considered after containment, but the immediate need is to try to recover the funds.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable email access for all employees to prevent further attacks

    Why it's wrong here

    This is too drastic and would disrupt business operations.

  • Launch a full forensic investigation to identify the source

    Why it's wrong here

    Investigation can occur after containment and recovery.

  • Notify the board within the 24-hour window as per policy

    Why it's wrong here

    Reporting is important but should follow immediate recovery attempts.

  • Immediately contact the bank to attempt to reverse the wire transfer

    Why this is correct

    Swift action can help recover the funds before they are withdrawn.

About these practice questions

Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.