200-201 Security Concepts Practice Question
Which phase of the NIST Cybersecurity Framework involves actions to limit the impact of a cybersecurity incident?
⚠ Common exam trap
The trap is the overlap between Protect and Respond: both mention 'limiting impact,' so candidates pick Protect, but Protect is pre-incident while Respond is the active-incident phase.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Respond
The Respond function of the NIST Cybersecurity Framework (CSF) covers the actions taken once an incident is detected—containment, mitigation, analysis, and communication—to limit the impact and prevent further damage. It is the phase where incident response plans, communications, and mitigation activities are executed. This directly matches the question's wording about limiting the impact of an incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Respond
Why this is correct
Respond covers the actions taken once a cybersecurity incident is detected, containing its spread and limiting impact through response planning, communications, analysis, mitigation and improvements. It follows Detect and precedes Recover, which restores services, so it directly matches the stem's requirement to limit incident impact.
- ✗
Protect
Why it's wrong here
Protect covers safeguards such as access control, hardening and training applied before an incident, not actions taken to limit impact once one is underway. It is tempting because protective controls do reduce eventual damage, and Protect would be the correct phase when selecting preventive controls during framework implementation.
- ✗
Identify
Why it's wrong here
Identify is about understanding assets, business environment and risks beforehand; it produces no containment or impact-limiting actions during a live incident. It is tempting because asset inventory underpins later response, and Identify would be the correct phase when establishing an organisational risk baseline before incidents occur.
- ✗
Detect
Why it's wrong here
Detect concerns discovering and analysing events through monitoring and anomaly detection, not limiting the impact of an incident already confirmed. It is tempting because detection precedes containment, and Detect would be the correct phase when implementing SIEM alerting or continuous monitoring to find threats early.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.