Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A file server is actively renaming documents and generating ransom notes. The server hosts a shared drive used by finance, and users are still online. What is the best immediate action?

⚠ Common exam trap

Watch out — candidates often confuse 'stopping the attack' with 'shutting down the system,' but CompTIA emphasizes that isolation (disconnecting the network cable or disabling the port) is the first step in containment to preserve evidence and avoid data loss.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate the server from the network to contain the spread while preserving evidence.

Isolating the server from the network stops the ransomware from encrypting more files or spreading laterally, while preserving volatile evidence (e.g., running processes, memory contents) needed for forensic analysis. In a live incident, immediate disconnection (not shutdown) is the standard containment step per NIST SP 800-61 and SANS incident response guidelines, as it halts the attack without destroying data in memory or logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Shut the server down immediately to stop all activity as fast as possible.

    Why it's wrong here

    Immediate shutdown stops encryption but destroys volatile evidence like memory-resident malware, open network connections, encryption keys in RAM, and process artifacts. Also sudden power loss can cause filesystem corruption, making forensic analysis harder. The priority is containment, not just stopping activity, because preserving evidence is critical for identifying the ransomware variant and entry vector. Thus isolation is preferred over shutdown.

  • Isolate the server from the network to contain the spread while preserving evidence.

    Why this is correct

    Network isolation is the best immediate containment step because it limits lateral movement and reduces the chance that ransomware spreads to other systems or continues encrypting shared data. It is also less destructive than a hard shutdown, which can interfere with evidence collection. In incident response, containment should stop the impact while preserving the ability to investigate what happened.

  • Restore the file server from backup before checking whether the infection is still active.

    Why it's wrong here

    Restoring from backup before eradication may leave the backdoor or rootkit intact, allowing reinfection. It also overwrites current forensic evidence and may restore partial or unencrypted data, but if the threat persists, new encryption will occur. Need to first contain, eradicate, and then restore from clean backups after verifying the backup integrity and ensuring no active infection.

  • Run a full antivirus scan and wait for the results before taking any other action.

    Why it's wrong here

    Antivirus scans rely on signatures and heuristics; for novel ransomware, detection may be delayed or missed. During the scan, the ransomware continues encrypting files and spreading to network shares, so active containment (isolation) is required immediately. A scan is a post-containment step, not a first response.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.