hardMultiple Select
200-201 Practice Question: Which THREE of the following are common elements…
Which THREE of the following are common elements of an incident response policy?
⚠ Common exam trap
Cisco often tests the distinction between an incident response policy (which includes definitions, roles, and procedures) and other security policies like data classification or acceptable use, leading candidates to mistakenly include elements from adjacent policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Procedures for containment and eradication
An incident response policy must define what constitutes a security incident (E), because without a clear definition of triggering events, the organization cannot consistently determine when the IR process should be activated. It must also specify the roles and responsibilities of the incident response team (C), so that each member knows who leads, who investigates, who communicates, and who has authority to act during an incident. Additionally, it must include procedures for containment and eradication (B), since these are core phases of the incident response lifecycle that limit damage and remove the threat from the environment. Options A and D are incorrect in this context: data classification levels (A) belong to a data governance or information classification policy, and acceptable use of company resources (D) belongs to an acceptable use policy, not specifically to an incident response policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data classification levels
Why it's wrong here
Data classification levels belong in a data governance or information classification policy, labelling sensitivity, not incident response. It is tempting because classification guides handling during breaches, but an incident response policy instead defines roles, communication plans, escalation paths, and containment procedures.
- ✓
Procedures for containment and eradication
Why this is correct
Containment and eradication procedures form a core incident response policy element, defining how to limit damage and remove the threat. This satisfies the stem's requirement for common policy components, alongside preparation, detection, analysis and post-incident activity, as structured in recognised frameworks such as NIST SP 800-61.
- ✓
Roles and responsibilities of the incident response team
Why this is correct
Roles and responsibilities define who triages, contains and eradicates an incident, satisfying the policy requirement for clear team accountability. Without assigned ownership, response actions stall during escalation. This element is standard in incident response policies alongside scope and communication procedures.
- ✗
Acceptable use of company resources
Why it's wrong here
Acceptable use of company resources belongs in a security policy or employee handbook, defining permitted behaviour, not incident response. It is tempting because both are security documents, but an incident response policy covers preparation, detection, containment, eradication, and recovery phases instead.
- ✓
Definition of what constitutes a security incident
Why this is correct
A definition of what constitutes a security incident is a foundational element, establishing the trigger criteria that determine when the incident response process activates. Without this scope, responders cannot consistently classify events or decide which warrant escalation, so the policy must specify the conditions, thresholds and event categories that qualify as incidents requiring formal handling.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.