easyMultiple Select
200-201 Practice Question: Which TWO actions should an analyst take when a…
Which TWO actions should an analyst take when a critical alert is triggered?
⚠ Common exam trap
Cisco often tests the misconception that immediate containment actions like powering off a system are always the correct first step, when in fact verification and preservation of evidence are prioritized to avoid destroying critical forensic data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify the alert with other sources
Option B is correct because verifying a critical alert against other sources (such as SIEM logs, EDR telemetry, IDS/IPS events, or host-based logs) confirms whether the alert represents a true positive before committing resources, reducing the risk of acting on a false positive. Option C is correct because once a critical alert is validated, the analyst should escalate it to the incident response team so that containment, eradication, and recovery follow the organization's documented IR process and chain-of-custody requirements. Option A is wrong because deleting alerts destroys evidence and audit trails and could mask a real compromise. Option D, while sometimes useful for context, is not one of the two primary actions required at the moment a critical alert fires. Option E is wrong because powering off a system can destroy volatile evidence in memory and may violate incident response procedures; isolation is preferred over shutdown.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the alert to reduce noise
Why it's wrong here
Deleting the alert destroys the audit trail and evidence required for investigation, reporting and compliance. It is tempting because it clears queue noise quickly, but genuine noise reduction uses tuning, suppression rules or false-positive marking, never deletion of a critical detection record.
- ✓
Verify the alert with other sources
Why this is correct
Correlating the alert against logs, endpoint telemetry and threat intelligence confirms whether the detection reflects genuine malicious activity or a false positive, preventing wasted escalation effort and establishing the factual basis needed before containment decisions.
- ✓
Escalate to incident response team
Why this is correct
Critical severity indicates potential major impact, so the analyst hands the validated incident to the incident response team, which holds the authority and specialised tooling for containment, eradication and recovery beyond the analyst's triage remit.
- ✗
Search for similar alerts in the past
Why it's wrong here
Historical correlation is a later triage step; the immediate priority is containing the threat and preserving volatile evidence. It is tempting because reviewing past similar alerts does build context and identify campaigns, but doing it before containment delays response to an active critical incident.
- ✗
Immediately power off the affected system
Why it's wrong here
Powering off destroys volatile memory, running processes and network connections that forensics needs, and may alert the attacker. It is tempting because it appears to stop the threat instantly, but isolation from the network achieves containment while preserving evidence for investigation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.