nerdexam
Cisco

200-201 · Question #174

An analyst received a ticket regarding a degraded processing capability for one of the HR department's servers. On the same day, an engineer noticed a disabled antivirus software and was not able to…

The correct answer is B. Detection. Discovering unusual system behavior and disabled antivirus indicates a potential incident, placing the investigation in the detection phase, where signs of compromise are identified and validated before moving to analysis or response actions.

Submitted by the_admin· Mar 6, 2026Security Policies and Procedures

Question

An analyst received a ticket regarding a degraded processing capability for one of the HR department's servers. On the same day, an engineer noticed a disabled antivirus software and was not able to determine when or why it occurred. According to the NIST Incident Handling Guide, what is the next phase of this investigation?

Options

  • ARecovery
  • BDetection
  • CEradication
  • DAnalysis

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    75% (24)
  • C
    16% (5)
  • D
    3% (1)

Explanation

Discovering unusual system behavior and disabled antivirus indicates a potential incident, placing the investigation in the detection phase, where signs of compromise are identified and validated before moving to analysis or response actions.

Topics

#incident response#NIST framework#incident detection

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice