Courseiva
Question 1,141 of 1,013
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A Linux web server was compromised through an outdated package. The team isolated the host, captured evidence, removed a malicious cron job, patched the vulnerable package, and confirmed no persistence remains. Which incident response phase are they primarily in now?

⚠ Common exam trap

Watch out — candidates often confuse the isolation step (Containment) with the overall phase, but the question emphasizes the removal of the malicious cron job and patching, which are definitive Eradication actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Eradication, because malicious artifacts and the underlying weakness are being removed.

The team has already identified the compromise, isolated the host, and removed the malicious cron job. Patching the vulnerable package addresses the root cause, which is the core of the Eradication phase. Confirming no persistence remains verifies that the eradication was successful, making this the current phase.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Identification, because the team is still confirming that the event happened.

    Why it's wrong here

    Identification happens when the incident is first detected and validated. In this scenario, the compromise has already been confirmed (the server was compromised via an outdated package), so the team is no longer in the identification phase. The current actions — removing malicious artifacts and patching the underlying weakness — are the hallmark of eradication, not identification.

  • Containment, because the host was isolated from the network.

    Why it's wrong here

    Containment involves isolating the affected system to prevent lateral movement and further damage, such as disconnecting the server from the network. This action was likely performed earlier as part of the incident response process. However, the question describes the team currently removing malicious artifacts and addressing the root cause (the outdated package), which is the eradication phase, not containment.

  • Eradication, because malicious artifacts and the underlying weakness are being removed.

    Why this is correct

    Eradication is the incident response phase dedicated to removing the adversary's presence entirely — deleting malware, eliminating persistence mechanisms, and remediating the root cause, such as the outdated package that was exploited. The scenario's description of removing malicious artifacts and the underlying weakness directly matches this phase. Unlike containment, which merely limits damage, eradication seeks to ensure the attacker cannot easily return.

  • Lessons learned, because the server has already been secured.

    Why it's wrong here

    Lessons learned is a post-incident activity that occurs after recovery and closure, where the team reviews what happened, evaluates the response, and documents improvements. Since the team is still actively removing malicious artifacts and fixing the underlying weakness, the incident has not yet reached recovery or closure. The question describes ongoing eradication, not the retrospective analysis of lessons learned.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.