Question 1,141 of 1,013
SY0-701 Security Operations Practice Question
A Linux web server was compromised through an outdated package. The team isolated the host, captured evidence, removed a malicious cron job, patched the vulnerable package, and confirmed no persistence remains. Which incident response phase are they primarily in now?
⚠ Common exam trap
Watch out — candidates often confuse the isolation step (Containment) with the overall phase, but the question emphasizes the removal of the malicious cron job and patching, which are definitive Eradication actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Eradication, because malicious artifacts and the underlying weakness are being removed.
The team has already identified the compromise, isolated the host, and removed the malicious cron job. Patching the vulnerable package addresses the root cause, which is the core of the Eradication phase. Confirming no persistence remains verifies that the eradication was successful, making this the current phase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identification, because the team is still confirming that the event happened.
Why it's wrong here
Identification happens when the incident is first detected and validated. In this scenario, the compromise has already been confirmed (the server was compromised via an outdated package), so the team is no longer in the identification phase. The current actions — removing malicious artifacts and patching the underlying weakness — are the hallmark of eradication, not identification.
- ✗
Containment, because the host was isolated from the network.
Why it's wrong here
Containment involves isolating the affected system to prevent lateral movement and further damage, such as disconnecting the server from the network. This action was likely performed earlier as part of the incident response process. However, the question describes the team currently removing malicious artifacts and addressing the root cause (the outdated package), which is the eradication phase, not containment.
- ✓
Eradication, because malicious artifacts and the underlying weakness are being removed.
Why this is correct
Eradication is the incident response phase dedicated to removing the adversary's presence entirely — deleting malware, eliminating persistence mechanisms, and remediating the root cause, such as the outdated package that was exploited. The scenario's description of removing malicious artifacts and the underlying weakness directly matches this phase. Unlike containment, which merely limits damage, eradication seeks to ensure the attacker cannot easily return.
- ✗
Lessons learned, because the server has already been secured.
Why it's wrong here
Lessons learned is a post-incident activity that occurs after recovery and closure, where the team reviews what happened, evaluates the response, and documents improvements. Since the team is still actively removing malicious artifacts and fixing the underlying weakness, the incident has not yet reached recovery or closure. The question describes ongoing eradication, not the retrospective analysis of lessons learned.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.