SY0-701 Security Operations Practice Question
A help desk ticket confirms that a user entered corporate credentials into a fake sign-in page. Minutes later, the security team finds a new mailbox forwarding rule and evidence that the attacker added backup MFA codes. After disabling the account, what should the team do next to support containment and recovery?
⚠ Common exam trap
It's easy for candidates to assume MFA is a silver bullet and overlook that attackers can register their own MFA devices or use session hijacking, making credential reset alone insufficient without session revocation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Revoke active sessions and reset the compromised credentials.
After disabling a compromised account, the immediate next step is to revoke all active sessions and reset the credentials. This ensures the attacker cannot maintain access via existing tokens or session cookies, and the new password invalidates any cached or stolen credentials. This aligns with the NIST SP 800-61 incident response containment phase, which prioritizes cutting off active attacker access before further investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wait for the user to confirm the behavior before taking any further steps.
Why it's wrong here
Delaying action to wait for user confirmation is unacceptable because the ticket already provides concrete evidence of compromise, including mailbox changes and MFA backup code manipulation. In incident response, immediate containment takes precedence over user interviews; every minute the attacker retains active sessions and stolen credentials, they can exfiltrate sensitive data, send phishing emails, or pivot to other systems. The user's verbal confirmation would not alter the technical reality that the account has been abused and must be secured now.
- ✗
Reimage the user's laptop before reviewing the account activity.
Why it's wrong here
Reimaging the user's laptop is a lateral step that fails to address the confirmed cloud account compromise. The attacker has manipulated MFA backup codes and likely holds session tokens that are independent of the endpoint; disabling local access does not invalidate those tokens or prevent the attacker from using a different device. In proper incident response, identity-focused containment (revoking sessions, resetting credentials) must precede endpoint remediation, and the reimage is only relevant if endpoint malware is suspected as the intrusion vector.
- ✓
Revoke active sessions and reset the compromised credentials.
Why this is correct
After disabling the account, the next step is to cut off any valid sessions and reset the credential set so the attacker cannot continue using stolen access. Because the compromise includes mailbox changes and MFA backup code manipulation, session revocation and credential reset are essential containment and recovery tasks.
- ✗
Close the ticket because MFA was enabled and should have prevented access.
Why it's wrong here
The presence of MFA does not guarantee security, and this ticket explicitly states that MFA backup code manipulation occurred, proving the MFA was circumvented. Attackers can bypass MFA via session token theft (pass-the-cookie), adversary-in-the-middle phishing (e.g., Evilginx), or by abusing recovery mechanisms like backup codes. Closing the ticket would ignore active, ongoing unauthorized access to corporate mail, leaving the account compromised and potentially allowing lateral movement throughout the organization.
Go deeper
Related to this question
Learn chapter
Identity and Access Management
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.