hardMultiple ChoiceObjective-mapped
200-201 Practice Question: A security analyst at a financial services company
You are a security analyst at a financial services company. The company's security policy mandates that all sensitive data must be encrypted at rest and in transit. A recent internal audit reveals that a database containing customer personally identifiable information (PII) is stored on a server that uses unencrypted storage volumes. The database is accessed by internal applications via unencrypted connections. The policy also requires quarterly vulnerability scans, and the latest scan shows that the server has a critical vulnerability in the database software. Additionally, the server's firewall rules permit inbound traffic from the entire corporate network to the database port. The company's incident response policy requires that any violation of data protection policies be escalated within 24 hours. The IT manager asks you to prioritize actions. What should you do first?
⚠ Common exam trap
Cisco often tests the concept that patching a critical vulnerability takes precedence over other security controls, even when policy mandates encryption or escalation, because the vulnerability represents an active, exploitable risk that can bypass all other defenses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply the critical security patch to the database software
The most immediate threat is the critical vulnerability in the database software, which could allow remote code execution or data exfiltration without any authentication. Patching this vulnerability directly reduces the risk of exploitation, which is the highest priority in a security incident. Encryption and firewall restrictions are important but do not address an actively exploitable software flaw.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable encryption on the storage volumes and database connections
Why it's wrong here
This is important but not the most urgent action.
- ✓
Apply the critical security patch to the database software
Why this is correct
Patching the critical vulnerability reduces immediate risk of exploitation.
- ✗
Escalate the violation to management within 24 hours
Why it's wrong here
Escalation should happen but after taking immediate action.
- ✗
Restrict firewall access to only authorized application servers
Why it's wrong here
This is a good step but not as urgent as patching.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 979 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.