Courseiva
mediumMultiple ChoiceObjective-mapped

200-201 Practice Question: A security operations analyst for a medium-sized…

You are a security operations analyst for a medium-sized enterprise. The company's security policy requires that all endpoint devices have antivirus software installed and updated. During a routine check, you find that a group of 50 laptops used by the sales team have not received antivirus updates for over three months. The policy also states that any non-compliant devices must be quarantined from the network until they are remediated. The sales team manager argues that quarantining the laptops will disrupt critical sales activities. The company's incident response policy has a clause that allows for temporary exceptions in business-critical situations, but requires approval from the CISO. What is the best course of action?

⚠ Common exam trap

Cisco often tests the balance between strict policy enforcement and business continuity, trapping candidates who choose immediate quarantine (Option B) without considering documented exception processes, or who choose to update without quarantine (Option D) thinking it's a practical workaround.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Request a temporary exception from the CISO while expediting the updates

It balances security policy compliance with business continuity. The incident response policy explicitly allows temporary exceptions for business-critical situations with CISO approval, and expediting the updates ensures the 50 laptops are remediated quickly. Quarantining without considering the business impact could violate the company's own exception clause, while ignoring the issue or updating without quarantining bypasses the security controls required by policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Ignore the issue to avoid disrupting sales activities

    Why it's wrong here

    Ignoring the policy increases risk of malware infection.

  • Quarantine the laptops immediately as per policy

    Why it's wrong here

    Quarantine may be too disruptive without CISO approval.

  • Request a temporary exception from the CISO while expediting the updates

    Why this is correct

    The exception process allows business continuity while addressing the issue.

  • Update the antivirus without quarantining, then report to management

    Why it's wrong here

    Updating is good, but the policy requires quarantine; exception must be approved.

About these practice questions

This 200-201 question is part of Courseiva's 979-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.