SY0-701 Security Operations Practice Question
A help desk ticket reports that a user's Microsoft 365 mailbox sent hundreds of messages to external contacts, and the user says they are still receiving MFA prompts they did not start. The attacker may still have an active web session. What is the best first containment action?
⚠ Common exam trap
Many exam-takers think deleting the sent messages is sufficient containment, failing to recognize that the attacker's active session must be terminated to stop ongoing compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Revoke the account's active sessions and reset the password immediately.
The user is still receiving unsolicited MFA prompts, indicating an attacker likely has an active web session with a valid token. Revoking all active sessions immediately invalidates any existing tokens or cookies, while resetting the password ensures the attacker cannot re-authenticate. This is the fastest way to cut off the attacker's access and stop further abuse of the mailbox.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the suspicious sent messages and close the ticket.
Why it's wrong here
Simply deleting the suspicious sent messages is a reactive, evidence-destroying action. It does not terminate the attacker's active session or invalidate any stolen tokens or cookies, so they can continue to abuse the mailbox. Furthermore, the removed messages are often the only source of forensic data—such as exfiltration targets, malicious links, or attacker instructions—that incident responders need. Closing the ticket before containment is completed leaves the organization with an unresolved active compromise.
- ✓
Revoke the account's active sessions and reset the password immediately.
Why this is correct
Ending active sessions cuts off any stolen cookies or tokens that may still be valid, and resetting the password prevents immediate reentry. In an email compromise, the attacker often keeps access through browser sessions even after credentials change. Fast containment should focus on terminating current access paths first, then investigating forwarding rules, OAuth grants, and sign-in history.
- ✗
Wait until the end of the workday to avoid interrupting the user.
Why it's wrong here
Deferring containment until the end of the workday gives the attacker a prolonged window to exfiltrate additional data, modify mailbox rules for persistence, or launch more phishing campaigns from a trusted domain. In an incident response, time-to-containment is a critical metric because attacker dwell time directly correlates with blast radius. Even if the user is actively working, the account should be isolated immediately, and the user can be transitioned to a temporary account or offline access after the session and credential reset.
- ✗
Reimage the user's laptop before touching the email account.
Why it's wrong here
Imaging the user's laptop is an endpoint containment step that addresses persistence on the device, but it does not revoke the cloud-side session tokens, OAuth grants, or inbox rules that the attacker may have established. The attacker's mailbox access is often device-independent, so reimaging alone will not stop the unauthorized use of the Microsoft 365 account. Reimaging also is a time-consuming process that delays the immediate account-level containment, and it can destroy volatile endpoint artifacts that could connect the email abuse to a specific malware infection or credential stealer.
Go deeper
Related to this question
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.