Courseiva
easyMultiple Select

200-201 Practice Question: Which TWO actions should an analyst take when a…

Which TWO actions should an analyst take when a critical alert is triggered?

⚠ Common exam trap

Cisco often tests the misconception that immediate containment actions like powering off a system are always the correct first step, when in fact verification and preservation of evidence are prioritized to avoid destroying critical forensic data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the alert with other sources

Option B is correct because verifying a critical alert against other sources (such as SIEM logs, EDR telemetry, IDS/IPS events, or host-based logs) confirms whether the alert represents a true positive before committing resources, reducing the risk of acting on a false positive. Option C is correct because once a critical alert is validated, the analyst should escalate it to the incident response team so that containment, eradication, and recovery follow the organization's documented IR process and chain-of-custody requirements. Option A is wrong because deleting alerts destroys evidence and audit trails and could mask a real compromise. Option D, while sometimes useful for context, is not one of the two primary actions required at the moment a critical alert fires. Option E is wrong because powering off a system can destroy volatile evidence in memory and may violate incident response procedures; isolation is preferred over shutdown.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete the alert to reduce noise

    Why it's wrong here

    Deleting the alert destroys the audit trail and evidence required for investigation, reporting and compliance. It is tempting because it clears queue noise quickly, but genuine noise reduction uses tuning, suppression rules or false-positive marking, never deletion of a critical detection record.

  • ✓

    Verify the alert with other sources

    Why this is correct

    Correlating the alert against logs, endpoint telemetry and threat intelligence confirms whether the detection reflects genuine malicious activity or a false positive, preventing wasted escalation effort and establishing the factual basis needed before containment decisions.

  • ✓

    Escalate to incident response team

    Why this is correct

    Critical severity indicates potential major impact, so the analyst hands the validated incident to the incident response team, which holds the authority and specialised tooling for containment, eradication and recovery beyond the analyst's triage remit.

  • ✗

    Search for similar alerts in the past

    Why it's wrong here

    Historical correlation is a later triage step; the immediate priority is containing the threat and preserving volatile evidence. It is tempting because reviewing past similar alerts does build context and identify campaigns, but doing it before containment delays response to an active critical incident.

  • ✗

    Immediately power off the affected system

    Why it's wrong here

    Powering off destroys volatile memory, running processes and network connections that forensics needs, and may alert the attacker. It is tempting because it appears to stop the threat instantly, but isolation from the network achieves containment while preserving evidence for investigation.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.