Courseiva
hardMultiple Choice

200-201 GreenTech Inc Practice Question

GreenTech Inc. is a mid-sized company with 500 employees. The company uses Microsoft Exchange Online for email and has implemented a security policy that requires all employees to report suspicious emails to the security team. The security team uses a phishing simulation tool to train employees. In the past month, several employees have reported receiving emails that appear to be from the CEO requesting urgent wire transfers. The security team has blocked the sender domains and updated the email filters. However, one employee fell for the latest scam and transferred $50,000 to an account before reporting it. The security incident response plan states that any monetary loss must be reported to the board within 24 hours. The security analyst receives the report on Monday morning. What should the analyst do first based on the policy and best practices?

⚠ Common exam trap

200-201 often tests incident response prioritization — candidates pick the policy-driven action (notify the board) or the investigative action (forensics) because they sound 'correct' procedurally, but the exam expects you to recognize that immediate financial recovery actions take precedence over reporting and investigation in fraud incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Immediately contact the bank to attempt to reverse the wire transfer

The immediate priority in a wire-transfer fraud incident is to attempt to recover the funds by contacting the bank as soon as possible — the faster the bank is notified, the higher the chance of reversing or freezing the transfer. Best practices for BEC (Business Email Compromise) incidents place financial recovery first, before forensic investigation or internal notifications, because the 24-hour board notification window is still available while the wire recall window may be minutes to hours.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable email access for all employees to prevent further attacks

    Why it's wrong here

    Disabling email for all 500 employees halts business operations and does not address the fraudulent transfer, which the incident response plan requires reporting to the board within 24 hours. Account suspension is a containment step for an active, ongoing compromise of a specific mailbox, not for a completed business email compromise with monetary loss.

  • ✗

    Launch a full forensic investigation to identify the source

    Why it's wrong here

    Forensic investigation identifies the attacker's infrastructure and scope, but the plan mandates board notification within 24 hours of monetary loss. Investigation is the correct first step when the priority is determining breach extent before containment, not when a defined reporting deadline governs the immediate action.

  • ✗

    Notify the board within the 24-hour window as per policy

    Why it's wrong here

    Notifying the board satisfies the 24-hour monetary-loss clause but skips containment; the fraudulent transfer may still be recalled and the sender's infrastructure blocked. Board escalation suits confirmed, contained incidents. Immediate action is contacting the bank to freeze or recall funds while preserving evidence.

  • ✓

    Immediately contact the bank to attempt to reverse the wire transfer

    Why this is correct

    Contacting the bank immediately maximises the chance of recalling the wire before funds leave the recipient's account, directly addressing the $50,000 loss the incident response plan requires reporting to the board within 24 hours. Containment of financial impact takes precedence over notification, which follows once recovery is attempted.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.