Courseiva
hardMultiple Select

200-201 Practice Question: Which THREE of the following are common elements…

Which THREE of the following are common elements of an incident response policy?

⚠ Common exam trap

Cisco often tests the distinction between an incident response policy (which includes definitions, roles, and procedures) and other security policies like data classification or acceptable use, leading candidates to mistakenly include elements from adjacent policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Procedures for containment and eradication

An incident response policy must define what constitutes a security incident (E), because without a clear definition of triggering events, the organization cannot consistently determine when the IR process should be activated. It must also specify the roles and responsibilities of the incident response team (C), so that each member knows who leads, who investigates, who communicates, and who has authority to act during an incident. Additionally, it must include procedures for containment and eradication (B), since these are core phases of the incident response lifecycle that limit damage and remove the threat from the environment. Options A and D are incorrect in this context: data classification levels (A) belong to a data governance or information classification policy, and acceptable use of company resources (D) belongs to an acceptable use policy, not specifically to an incident response policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data classification levels

    Why it's wrong here

    Data classification levels belong in a data governance or information classification policy, labelling sensitivity, not incident response. It is tempting because classification guides handling during breaches, but an incident response policy instead defines roles, communication plans, escalation paths, and containment procedures.

  • ✓

    Procedures for containment and eradication

    Why this is correct

    Containment and eradication procedures form a core incident response policy element, defining how to limit damage and remove the threat. This satisfies the stem's requirement for common policy components, alongside preparation, detection, analysis and post-incident activity, as structured in recognised frameworks such as NIST SP 800-61.

  • ✓

    Roles and responsibilities of the incident response team

    Why this is correct

    Roles and responsibilities define who triages, contains and eradicates an incident, satisfying the policy requirement for clear team accountability. Without assigned ownership, response actions stall during escalation. This element is standard in incident response policies alongside scope and communication procedures.

  • ✗

    Acceptable use of company resources

    Why it's wrong here

    Acceptable use of company resources belongs in a security policy or employee handbook, defining permitted behaviour, not incident response. It is tempting because both are security documents, but an incident response policy covers preparation, detection, containment, eradication, and recovery phases instead.

  • ✓

    Definition of what constitutes a security incident

    Why this is correct

    A definition of what constitutes a security incident is a foundational element, establishing the trigger criteria that determine when the incident response process activates. Without this scope, responders cannot consistently classify events or decide which warrant escalation, so the policy must specify the conditions, thresholds and event categories that qualify as incidents requiring formal handling.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.