nerdexam
CiscoCisco

200-201 · Question #484

200-201 Question #484: Real Exam Question with Answer & Explanation

Sign in or unlock 200-201 to reveal the answer and full explanation for question #484. The question stem and answer options stay visible for context.

Submitted by kavita_s· Mar 6, 2026Security Policies and Procedures

Question

A network engineer informed a security team of a large amount of traffic and suspicious activity from an unknown source to the company DMZ server. The security team reviewed the data and identified a potential DDoS attempt. According to NIST, at which phase of incident response is the security team?

Options

  • Acontainment and eradication
  • Bdetection and analysis
  • Crecovery
  • Dpreparation

Unlock 200-201 to see the answer

You've previewed enough free 200-201 questions. Unlock 200-201 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#NIST SP 800-61#incident response#detection and analysis#DDoS
Full 200-201 PracticeBrowse All 200-201 Questions