Courseiva
hardMultiple Select

200-201 Practice Question: Which THREE are required steps in a proper…

Which THREE are required steps in a proper incident response procedure? (Choose three.)

⚠ Common exam trap

Cisco often tests the NIST incident response lifecycle phases and includes attractive distractors like Change Management or System Hardening that are related to security operations but are not part of the mandatory incident response procedure steps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Containment, Eradication, and Recovery

The three correct answers map directly to the phases of the NIST SP 800-61 incident response lifecycle. Option D, Detection and Analysis, is required because an incident must first be identified and its scope, impact, and nature analyzed before any response actions can be taken. Option B, Containment, Eradication, and Recovery, is required because responders must limit the damage (containment), remove the root cause or malware (eradication), and restore affected systems to normal operation (recovery). Option C, Post-Incident Activity (Lessons Learned), is required because after recovery the organization must review what happened, update procedures and controls, and document findings to improve future response. Option A, Change Management Processing, is a supporting IT governance process rather than a required incident response phase, and Option E, System Hardening, is a preventive security control performed outside the incident response lifecycle, so neither belongs in the core required steps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change Management Processing

    Why it's wrong here

    Change management governs production alterations; incident response instead requires containment, eradication and recovery actions, often under emergency change. It is tempting because responders do raise change records, yet the procedure's required steps are detection, containment and recovery, not change processing itself.

  • ✓

    Containment, Eradication, and Recovery

    Why this is correct

    Containment, eradication and recovery form the core sequential phases that stop the spread, remove the root cause and restore normal operations. They sit between identification and lessons learned, making them mandatory steps in any proper incident response procedure.

  • ✓

    Post-Incident Activity (Lessons Learned)

    Why this is correct

    Post-Incident Activity is the final phase of the incident response lifecycle, where the team reviews what happened and improves defences. NIST SP 800-61 names it a required step, satisfying the stem's demand for proper procedure phases.

  • ✓

    Detection and Analysis

    Why this is correct

    Detection and Analysis is the second phase of the incident response lifecycle, confirming whether an event is an incident and scoping its impact. NIST SP 800-61 lists it as required, satisfying the stem's demand for proper procedure steps.

  • ✗

    System Hardening

    Why it's wrong here

    Hardening is preventive work done before an incident, not a phase of the response lifecycle (preparation, detection, containment, eradication, recovery). It is tempting because hardened systems reduce attack surface, but that belongs to vulnerability management, not the required incident response steps the question asks for.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.