200-201 Security Policies and Procedures Practice Question
Which TWO are components of the NIST SP 800-61 Rev 2 Preparation phase? (Select two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Developing an incident response plan
NIST SP 800-61 Rev 2 places the creation of a formal, written IR plan—covering mission, goals, roles, communication paths, and escalation procedures—squarely in the Preparation phase, before any incident occurs. Option D (Creating an incident response team) is also correct because staffing and organizing the CSIRT (with defined roles, authority, and on-call procedures) is a core Preparation activity that must exist before incidents can be handled. By contrast, option A (Conducting lessons learned) belongs to the Post-Incident Activity phase, where the team reviews what happened and improves the plan. Option C (Containing the incident) is part of the Detection and Analysis/Containment, Eradication, and Recovery handling phase, not Preparation. Option E (Identifying indicators of compromise) is a Detection and Analysis activity, since IoCs are used to discover and validate incidents rather than to prepare for them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conducting lessons learned
Why it's wrong here
Lessons learned is the final Post-Incident Activity step, performed after recovery to improve future response; preparation precedes the incident entirely. It tempts because it is a recognised NIST SP 800-61 Rev 2 phase component, and would be correct when identifying what follows containment, eradication and recovery.
- ✓
Developing an incident response plan
Why this is correct
Drafting the incident response plan belongs to Preparation: it defines scope, roles, communication paths and playbooks before any incident occurs, satisfying the phase's requirement to establish capability in advance rather than during detection or containment.
- ✗
Containing the incident
Why it's wrong here
Containment belongs to the Containment, Eradication and Recovery phase, which follows detection and analysis; preparation covers only readiness activities such as tooling, training and communications plans. It tempts because containment is a familiar incident-handling activity, and would be correct when identifying steps taken once an incident has been confirmed.
- ✓
Creating an incident response team
Why this is correct
Establishing a dedicated incident response team directly satisfies the Preparation phase's requirement to define roles, responsibilities and reporting structures before an incident occurs. NIST SP 800-61 Rev 2 lists team formation alongside acquiring tools and preventing incidents, so this activity belongs to Preparation rather than detection, containment or post-incident handling.
- ✗
Identifying indicators of compromise
Why it's wrong here
Identifying indicators of compromise sits in Detection and Analysis, where evidence is examined to confirm and scope an incident; preparation instead establishes the capability to detect. It tempts because IoCs are strongly associated with incident response generally, and would be correct when describing activities performed after an incident is reported.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.