nerdexam
Cisco

200-201 · Question #167

An engineer discovered a breach, identified the threat's entry point, and removed access. The engineer was able to identify the host, the IP address of the threat actor, and the application the threat

Sign in or unlock 200-201 to reveal the answer and full explanation for question #167. The question stem and answer options stay visible for context.

Submitted by zhang_li· Mar 6, 2026Security Policies and Procedures

Question

An engineer discovered a breach, identified the threat's entry point, and removed access. The engineer was able to identify the host, the IP address of the threat actor, and the application the threat actor targeted. What is the next step the engineer should take according to the NIST SP 800-61 Incident handling guide?

Options

  • ARecover from the threat.
  • BAnalyze the threat.
  • CIdentify lessons learned from the threat.
  • DReduce the probability of similar threats.

Unlock 200-201 to see the answer

You've previewed enough free 200-201 questions. Unlock 200-201 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#NIST incident response#incident response phases#post-incident actions
Full 200-201 Practice