hardMultiple ChoiceObjective-mapped
200-201 GreenTech Inc Practice Question
GreenTech Inc. is a mid-sized company with 500 employees. The company uses Microsoft Exchange Online for email and has implemented a security policy that requires all employees to report suspicious emails to the security team. The security team uses a phishing simulation tool to train employees. In the past month, several employees have reported receiving emails that appear to be from the CEO requesting urgent wire transfers. The security team has blocked the sender domains and updated the email filters. However, one employee fell for the latest scam and transferred $50,000 to an account before reporting it. The security incident response plan states that any monetary loss must be reported to the board within 24 hours. The security analyst receives the report on Monday morning. What should the analyst do first based on the policy and best practices?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Immediately contact the bank to attempt to reverse the wire transfer
The immediate priority is to attempt to recover the funds. Contacting the bank to reverse the wire transfer should be the first step because there is a chance to stop or reverse the transaction if done promptly. Notifying the board (C) is required within 24 hours but is secondary to attempting recovery. A full forensic investigation (B) can be launched later, but it does not prevent monetary loss. Disabling email access (A) is overly disruptive and not the first action; it may be considered after containment, but the immediate need is to try to recover the funds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable email access for all employees to prevent further attacks
Why it's wrong here
This is too drastic and would disrupt business operations.
- ✗
Launch a full forensic investigation to identify the source
Why it's wrong here
Investigation can occur after containment and recovery.
- ✗
Notify the board within the 24-hour window as per policy
Why it's wrong here
Reporting is important but should follow immediate recovery attempts.
- ✓
Immediately contact the bank to attempt to reverse the wire transfer
Why this is correct
Swift action can help recover the funds before they are withdrawn.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.