FC0-U71 Security Practice Question
A user's workstation has become slow and shows unexpected pop-up windows even when no browser is open. A technician suspects malware and wants to reduce the risk of further compromise while investigating. Which TWO actions should the technician take FIRST? (Choose two.)
⚠ Common exam trap
The trap here is jumping straight to remediation such as scanning or reimaging, which can let active malware keep communicating or destroy the evidence needed to understand the scope of the incident.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the observed symptoms and note the time they began.
Containment and evidence preservation come before remediation. Disconnecting the workstation stops active communication with external infrastructure and prevents lateral spread, while documenting symptoms and timestamps preserves information needed for analysis. Scanning, reimaging, or sharing credentials either allows the threat to continue operating or destroys evidence, so those actions belong later in the response process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan while leaving the machine connected.
Why it's wrong here
Scanning is a reasonable later step, but doing it while the machine remains on the network allows active malware to continue communicating, exfiltrating data, or infecting other hosts during the scan. Containment should precede remediation because a scan can take a long time and does not stop ongoing malicious activity. Leaving the connection in place also risks the malware altering its behavior or disabling the scanner.
- ✗
Share the user's login credentials with the security team by email.
Why it's wrong here
Sending credentials by email exposes them to interception and violates the principle of limiting credential exposure. If the security team needs access, the credentials should be reset through a controlled process or the account should be accessed through administrative tools. Sharing passwords in plaintext does not help contain the suspected malware and introduces a new security risk during the investigation.
- ✓
Document the observed symptoms and note the time they began.
Why this is correct
Recording symptoms, timestamps, and the state of the machine preserves evidence and supports later analysis of how the infection occurred and what it affected. This documentation is valuable whether the machine is later reimaged or cleaned, and it helps identify other potentially compromised systems. Capturing this information early, before remediation changes the system, is a core incident-handling practice.
- ✗
Immediately reinstall the operating system without further checks.
Why it's wrong here
Reimaging destroys volatile evidence such as running processes, network connections, and temporary files that could reveal the malware family, its persistence mechanism, and whether other systems were contacted. Without that information, the organization cannot be sure the threat is fully removed or whether additional hosts are compromised. Reinstallation is a possible final step, not a first response to a suspected infection.
- ✓
Disconnect the workstation from the network.
Why this is correct
Disconnecting the workstation from the network immediately limits the malware's ability to communicate with command-and-control servers, download additional payloads, or spread to other systems on the local network. It preserves the current state of the machine for investigation while containing the incident. This is a standard first containment step when active malware is suspected and precedes deeper analysis or remediation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.