nerdexam
Cisco

200-201 · Question #287

Refer to the exhibit. A suspicious IP address is tagged by Threat Intelligence as a brute-force attempt source. After the attacker produces many of failed login entries it successfully compromises…

The correct answer is C. employee 4. Based on the provided incident response diagram and the correct answer, employee 4 is responsible for the detection step in the incident response process.

Submitted by jordan8· Mar 6, 2026Security Policies and Procedures

Question

Refer to the exhibit. A suspicious IP address is tagged by Threat Intelligence as a brute-force attempt source. After the attacker produces many of failed login entries it successfully compromises the account. Which stakeholder is responsible for the incident response detection step?

Exhibit

200-201 question #287 exhibit

Options

  • Aemployee 2
  • Bemployee 3
  • Cemployee 4
  • Demployee 5

How the community answered

(57 responses)
  • A
    7% (4)
  • B
    18% (10)
  • C
    70% (40)
  • D
    5% (3)

Why each option

Based on the provided incident response diagram and the correct answer, employee 4 is responsible for the detection step in the incident response process.

Aemployee 2

Employee 2 is associated with a different incident response phase according to the diagram, not specifically detection.

Bemployee 3

The provided correct answer indicates that employee 4 (option C) is responsible for detection, not employee 3 (option B), despite any visual ambiguity in the exhibit.

Cemployee 4Correct

Assuming the provided correct answer C aligns with the intended mapping of roles in the incident response diagram, employee 4 is the stakeholder responsible for the detection step, which involves identifying the occurrence of security incidents.

Demployee 5

Employee 5 is responsible for a different phase of incident response, according to the diagram, and not directly for the detection step.

Concept tested: Incident response roles and responsibilities

Source: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final

Topics

#Incident response roles#Detection phase#SOC#Brute-force

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice