200-201 Security Policies and Procedures Practice Question
In the NIST SP 800-61 Rev 2 incident response process, which phase involves documenting lessons learned and updating the incident response plan?
⚠ Common exam trap
Cisco often tests the misconception that lessons learned and plan updates occur during the Detection and Analysis phase, because candidates confuse the analysis of the incident itself with the analysis of the incident response process performance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Post-Incident Activity
The Post-Incident Activity phase of NIST SP 800-61 Rev 2 is specifically designed for conducting a lessons learned meeting, documenting findings, and updating the incident response plan based on those insights. This phase ensures continuous improvement of the incident response process by capturing what worked, what didn't, and what changes are needed for future incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Containment, Eradication, and Recovery
Why it's wrong here
Containment, Eradication and Recovery covers limiting damage, removing the threat and restoring services; lessons learned and plan updates belong to Post-Incident Activity. It is tempting because recovery work often generates findings, but documentation of those findings occurs after the incident closes.
- ✗
Detection and Analysis
Why it's wrong here
Detection and Analysis identifies and scopes the incident; it produces findings but not the formal lessons-learned review or plan revision. It is tempting because analysis generates the technical detail later documented, yet NIST places that documentation in Post-Incident Activity, after recovery completes.
- ✓
Post-Incident Activity
Why this is correct
Post-Incident Activity covers the lessons-learned meeting and revision of the incident response plan, closing the loop after eradication and recovery. It is the final NIST SP 800-61 Rev 2 phase, distinct from preparation, detection and analysis, and containment, eradication and recovery.
- ✗
Preparation
Why it's wrong here
Preparation establishes tools, training and plans before an incident occurs; it cannot capture lessons from an event that has not happened. It is tempting because plan updates are a preparation activity, yet the NIST phase that documents lessons learned from a completed incident is Post-Incident Activity.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.