SY0-701 Security Operations Practice Question
A file server is actively renaming documents and generating ransom notes. The server hosts a shared drive used by finance, and users are still online. What is the best immediate action?
⚠ Common exam trap
Watch out — candidates often confuse 'stopping the attack' with 'shutting down the system,' but CompTIA emphasizes that isolation (disconnecting the network cable or disabling the port) is the first step in containment to preserve evidence and avoid data loss.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the server from the network to contain the spread while preserving evidence.
Isolating the server from the network stops the ransomware from encrypting more files or spreading laterally, while preserving volatile evidence (e.g., running processes, memory contents) needed for forensic analysis. In a live incident, immediate disconnection (not shutdown) is the standard containment step per NIST SP 800-61 and SANS incident response guidelines, as it halts the attack without destroying data in memory or logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Shut the server down immediately to stop all activity as fast as possible.
Why it's wrong here
Immediate shutdown stops encryption but destroys volatile evidence like memory-resident malware, open network connections, encryption keys in RAM, and process artifacts. Also sudden power loss can cause filesystem corruption, making forensic analysis harder. The priority is containment, not just stopping activity, because preserving evidence is critical for identifying the ransomware variant and entry vector. Thus isolation is preferred over shutdown.
- ✓
Isolate the server from the network to contain the spread while preserving evidence.
Why this is correct
Network isolation is the best immediate containment step because it limits lateral movement and reduces the chance that ransomware spreads to other systems or continues encrypting shared data. It is also less destructive than a hard shutdown, which can interfere with evidence collection. In incident response, containment should stop the impact while preserving the ability to investigate what happened.
- ✗
Restore the file server from backup before checking whether the infection is still active.
Why it's wrong here
Restoring from backup before eradication may leave the backdoor or rootkit intact, allowing reinfection. It also overwrites current forensic evidence and may restore partial or unencrypted data, but if the threat persists, new encryption will occur. Need to first contain, eradicate, and then restore from clean backups after verifying the backup integrity and ensuring no active infection.
- ✗
Run a full antivirus scan and wait for the results before taking any other action.
Why it's wrong here
Antivirus scans rely on signatures and heuristics; for novel ransomware, detection may be delayed or missed. During the scan, the ransomware continues encrypting files and spreading to network shares, so active containment (isolation) is required immediately. A scan is a post-containment step, not a first response.
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.