200-201 exam dumps

200-201 practice question 329 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 329

Select 4

A cybersecurity operations team is developing their organization's incident response plan in alignment with NIST.SP800-61. Which of the following are key elements that must be included in the plan to ensure proper incident handling and response?

  1. A

    Preparation phase to establish policies, tools, and training

  2. B

    Incident containment strategies to minimize the impact of attacks

  3. C

    Detailed list of all network devices and their configurations

  4. D

    Root cause analysis and lessons learned after an incident

  5. E

    Coordination with law enforcement and external entities when necessary

  6. F

    A log of all employee vacation schedules

Show answer and explanation

Correct answers: A, B, D, E

Explanation

NIST.SP800-61 outlines four key phases of an incident response plan: preparation, detection and analysis, containment/eradication/recovery, and post-incident activities. Preparation ensures readiness, while containment strategies mitigate damage. Post-incident activities like lessons learned enhance future responses. Coordination with external entities is vital for compliance and support. Elements unrelated to incident response, such as vacation schedules or generalized IT inventory, do not align with NIST's guidelines.

  • A. Correct.

    Preparation is a critical element of NIST.SP800-61's incident response plan, as it ensures the organization is equipped with the necessary resources to handle incidents effectively.

  • B. Correct.

    Incident containment strategies are essential for limiting the damage caused during an incident and are a core component of the incident response process.

  • C. Incorrect.

    While maintaining a list of network devices may be useful for IT operations, it is not explicitly part of the incident response plan as defined by NIST.SP800-61.

  • D. Correct.

    Conducting a root cause analysis and documenting lessons learned is an important step to improve future response efforts and reduce the likelihood of similar incidents.

  • E. Correct.

    Coordination with external entities, including law enforcement, is a key aspect of managing incidents, especially when dealing with legal or regulatory requirements.

  • F. Incorrect.

    A log of employee vacation schedules is unrelated to incident response planning and does not contribute to handling or mitigating cybersecurity incidents.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam