Courseiva
Security OperationseasyMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A file server begins encrypting documents, and the SOC confirms the activity is malicious. Which incident response step should happen first to limit further damage?

⚠ Common exam trap

CompTIA often tests the misconception that recovery (e.g., restoring from backup) is the first priority, but containment must come first to stop the active damage and prevent reinfection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Containment

Containment is the correct first step because it isolates the compromised file server from the network, preventing the ransomware from encrypting additional shares or spreading laterally. The SMB protocol (port 445) used for file sharing would be blocked at the switch or firewall, halting further encryption of documents. This aligns with the NIST SP 800-61 incident response lifecycle, where containment precedes eradication and recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Lessons learned

    Why it's wrong here

    Lessons learned is a post-incident review phase focused on process improvement, not an immediate response action. During active ransomware encryption, conducting lessons learned would waste critical time and do nothing to halt propagation or preserve evidence. It occurs after eradication and recovery are complete, so selecting it misunderstands the incident response lifecycle order.

  • Containment

    Why this is correct

    Containment is the immediate priority in incident response, isolating affected systems, blocking network communications, disabling compromised accounts, and preserving forensic evidence while stopping ongoing encryption. For a file server actively encrypting, containment actions like taking the server offline, segmenting VLANs, or revoking account tokens minimize further damage and buy time for eradication. This aligns with NIST SP 800-61 and CompTIA's incident response phases where containment precedes eradication and recovery.

  • Recovery

    Why it's wrong here

    Recovery restores systems from clean backups, validates data integrity, and returns business operations to normal only after the adversary is removed. Attempting recovery during an active encryption event is dangerous because reinfection may occur and backups could be encrypted or corrupted, so recovery is appropriately sequenced later in the incident response process. Therefore, while recovery is necessary, it is not the correct first action.

  • Post-incident reporting

    Why it's wrong here

    Post-incident reporting involves documenting timelines, root cause analysis, indicators of compromise, and regulatory notifications after the incident is resolved. It provides crucial compliance and improvement value, but it is a final step that cannot halt an ongoing encryption attack or reduce the current blast radius. Selecting it confuses retrospective documentation with real-time incident containment.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.