Courseiva
easyMultiple Choice

Incident Response Policy Elements

A company wants to ensure that employees report security incidents immediately. Which policy element is most important to include?

⚠ Common exam trap

Cisco often tests the distinction between preventive/technical controls (encryption, passwords, acceptable use) and procedural/response controls (reporting procedures), leading candidates to confuse a security best practice with the specific policy element needed for incident reporting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define mandatory reporting procedures and contact information

The core purpose of an incident response policy is to ensure timely reporting. Without mandatory reporting procedures and clear contact information, employees may delay or fail to report security incidents, increasing dwell time and potential damage. This directly supports the incident response lifecycle (NIST SP 800-61) by establishing a clear chain of communication for initial detection and reporting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Specify encryption standards for data at rest

    Why it's wrong here

    Encryption standards govern data protection, not employee behaviour, so they cannot compel immediate incident reporting. It is tempting because encryption is a core security control, and would be the right element when the requirement is protecting data at rest or in transit rather than establishing reporting duties.

  • ✗

    List acceptable uses of company resources

    Why it's wrong here

    Acceptable-use rules constrain how resources may be used, not how quickly incidents must be reported, so they do not drive immediate notification. It is tempting because acceptable-use clauses are standard policy content, and would be correct when the objective is limiting misuse of company systems rather than mandating incident reporting.

  • ✓

    Define mandatory reporting procedures and contact information

    Why this is correct

    Mandatory reporting procedures with contact details remove ambiguity about when, how and to whom incidents are escalated, directly satisfying the stem's requirement for immediate employee reporting. Without defined channels, staff delay or misroute notifications, extending attacker dwell time.

  • ✗

    Require complex passwords for all accounts

    Why it's wrong here

    Password complexity governs credential strength at authentication; it does nothing to prompt or channel incident reporting. It is tempting because strong authentication is a genuine security control, and it would be the right element when the requirement is resisting brute-force or credential-stuffing attacks rather than encouraging timely disclosure.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.