200-201 exam dumps

200-201 practice question 344 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 344

Single answer

A cybersecurity analyst is tasked with aligning organizational stakeholders with the NIST Incident Response (IR) Lifecycle as part of a compliance effort. Which of the following stakeholders is MOST responsible for overseeing the 'Detection and Analysis' category under the NIST IR framework?

  1. A

    IT Operations Team

  2. B

    Incident Response Team (IRT)

  3. C

    Executive Leadership

  4. D

    Legal and Compliance Team

Show answer and explanation

Correct answer: B

Explanation

The 'Detection and Analysis' category of the NIST Incident Response Lifecycle is centered around identifying potential security events, analyzing them for legitimacy, and determining their impact. The Incident Response Team (IRT) is specifically trained and equipped for this role, whereas other stakeholders like IT Operations or Legal teams have supporting or peripheral responsibilities. Therefore, the IRT is the most appropriate choice for handling this category.

  • A. Incorrect.

    The IT Operations Team generally supports the implementation and maintenance of systems but is not primarily responsible for detecting and analyzing incidents. Their role is more reactive when systems go down or need updates.

  • B. Correct.

    The Incident Response Team (IRT) is directly tasked with identifying, analyzing, and confirming security events as incidents. They are the primary actors in the 'Detection and Analysis' phase of the NIST IR framework, making them the correct choice.

  • C. Incorrect.

    Executive Leadership focuses on approving budgets, strategies, and making high-level decisions. They are not directly involved in the 'Detection and Analysis' process.

  • D. Incorrect.

    The Legal and Compliance Team ensures compliance with legal and regulatory requirements but does not have direct involvement in the technical detection and analysis of security incidents.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam