SY0-701 Security Operations Practice Question
A user reports a ransomware note on one department file share, but other departments are still working normally. What is the best first containment action?
⚠ Common exam trap
Candidates often choose Option A (full network shutdown) because they think it is the safest action, but the exam emphasizes precise, least-disruptive containment that preserves evidence and limits business impact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the affected file share or server from the network.
The immediate priority in a ransomware incident is to contain the threat by isolating the affected system to prevent lateral movement. Disconnecting the file share or server from the network stops the ransomware from encrypting additional files or spreading to other departments via SMB or other protocols. This aligns with the NIST SP 800-61 containment strategy, which emphasizes rapid isolation without disrupting unaffected systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Shut down the entire company network immediately.
Why it's wrong here
A full network shutdown is an extreme containment measure that unnecessarily halts all business operations, including unrelated critical services, causing significant collateral damage. Beyond the disruption, it destroys volatile forensic evidence such as memory contents, active processes, and established network connections, which are essential for understanding the attack. Effective incident response requires isolating the specific affected file share or server to contain the threat promptly while preserving evidence and minimizing operational impact.
- ✓
Disconnect the affected file share or server from the network.
Why this is correct
Isolating the affected system is the best first containment step because it helps stop the malware from spreading while preserving the rest of the environment. The goal in early incident response is to reduce impact quickly without causing unnecessary downtime. Once contained, responders can investigate scope, preserve evidence, and begin eradication and recovery.
- ✗
Delete the ransom note and wait to see whether the problem returns.
Why it's wrong here
Deleting the ransom note only removes an observable indicator; it does nothing to eliminate the malware's executable, scheduled tasks, or persistence mechanisms that continue to encrypt files and propagate laterally. Waiting to see if the problem returns gives the adversary time to expand access, exfiltrate data, or deploy additional payloads, worsening the incident's scope. The note itself is critical forensic evidence—its content, hashes, and metadata can help identify the ransomware family and attacker, so removing it is counterproductive.
- ✗
Restore the share immediately before checking what caused the incident.
Why it's wrong here
Restoring the share from backup before determining the root cause can reintroduce the threat actor's foothold if the initial compromise vector—such as a backdoor, compromised account, or vulnerable service—remains active and unmitigated. It also overwrites the original encrypted files and any artifacts left by the attacker, destroying evidence needed for a proper forensic investigation. The correct sequence is to first contain the affected system, investigate the cause and scope, then eradicate the threat on the host and network, and only then proceed with recovery from clean backups.
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
SMB
SMB is a network file-sharing protocol that allows applications to read, write, and request services from server programs in a computer network.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.