Courseiva
Security Concepts →easyMultiple Choice

200-201 Security Concepts Practice Question

Which phase of the NIST Cybersecurity Framework involves actions to limit the impact of a cybersecurity incident?

⚠ Common exam trap

The trap is the overlap between Protect and Respond: both mention 'limiting impact,' so candidates pick Protect, but Protect is pre-incident while Respond is the active-incident phase.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Respond

The Respond function of the NIST Cybersecurity Framework (CSF) covers the actions taken once an incident is detected—containment, mitigation, analysis, and communication—to limit the impact and prevent further damage. It is the phase where incident response plans, communications, and mitigation activities are executed. This directly matches the question's wording about limiting the impact of an incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Respond

    Why this is correct

    Respond covers the actions taken once a cybersecurity incident is detected, containing its spread and limiting impact through response planning, communications, analysis, mitigation and improvements. It follows Detect and precedes Recover, which restores services, so it directly matches the stem's requirement to limit incident impact.

  • ✗

    Protect

    Why it's wrong here

    Protect covers safeguards such as access control, hardening and training applied before an incident, not actions taken to limit impact once one is underway. It is tempting because protective controls do reduce eventual damage, and Protect would be the correct phase when selecting preventive controls during framework implementation.

  • ✗

    Identify

    Why it's wrong here

    Identify is about understanding assets, business environment and risks beforehand; it produces no containment or impact-limiting actions during a live incident. It is tempting because asset inventory underpins later response, and Identify would be the correct phase when establishing an organisational risk baseline before incidents occur.

  • ✗

    Detect

    Why it's wrong here

    Detect concerns discovering and analysing events through monitoring and anomaly detection, not limiting the impact of an incident already confirmed. It is tempting because detection precedes containment, and Detect would be the correct phase when implementing SIEM alerting or continuous monitoring to find threats early.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.