nerdexam
Cisco

200-201 · Question #537

A company recently encountered a breach. Critical services went through a disturbance and the integrity of the data was altered. An engineer is investigating the issue and searching through the logs…

The correct answer is C. detection and analysis. Searching SIEM logs to identify what happened and confirm the nature of the breach is part of the detection and analysis phase, where analysts investigate alerts, gather evidence, and validate the

Submitted by deeparc· Mar 6, 2026Security Monitoring

Question

A company recently encountered a breach. Critical services went through a disturbance and the integrity of the data was altered. An engineer is investigating the issue and searching through the logs in the SIEM. Which phase of the incident response is an engineer working on?

Options

  • Apost-incident and lessons learned
  • Brecovery and restoration
  • Cdetection and analysis
  • Dcontainment and eradication

How the community answered

(19 responses)
  • A
    16% (3)
  • B
    5% (1)
  • C
    74% (14)
  • D
    5% (1)

Explanation

Searching SIEM logs to identify what happened and confirm the nature of the breach is part of the detection and analysis phase, where analysts investigate alerts, gather evidence, and validate the

Topics

#Incident response#Detection and analysis#SIEM#Log investigation

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice