SY0-701 Security Operations Practice Question
A security analyst at a financial firm detects an unusual spike in outbound network traffic from a database server that normally only communicates with internal web servers. The traffic is directed to numerous external IP addresses in various countries. According to established incident response procedures, what should be the analyst's immediate next step?
⚠ Common exam trap
Test-takers frequently confuse 'immediate containment' with 'immediate notification' or 'immediate remediation,' but the SY0-701 incident response framework prioritizes stopping the active threat (containment) over escalation or scanning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the server from the network at the switch level.
Disconnecting the server at the switch level (e.g., shutting down the switch port or placing it in a quarantine VLAN) is the immediate containment step per incident response procedures. This stops the outbound data exfiltration without risking data loss or corruption that could occur from a hard power-off, and it preserves volatile memory evidence for forensic analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disconnect the server from the network at the switch level.
Why this is correct
Isolating the server at the switch port is the proper containment step because it severs the network path used for data exfiltration without disrupting the host's power or volatile memory. This preserves running processes, open network connections, and other live forensic evidence, aligning with the NIST incident response framework's containment phase. It immediately halts the unauthorized data transfer while allowing the analyst to gather evidence from the live system.
- ✗
Run a comprehensive antivirus scan on the server.
Why it's wrong here
A comprehensive antivirus scan is a detection and eradication activity, not a containment measure. During the scan, the server remains connected to the network, so the data exfiltration continues unabated, and the scan's intensive I/O activity may trigger malware countermeasures that destroy volatile evidence. Prioritizing the scan over containment delays the critical action of stopping the breach and may alert the attacker, worsening the incident.
When this WOULD be correct
This would be correct if the question described a suspected malware infection on a non-critical system with no signs of active data exfiltration, and the incident response procedure required initial triage with antivirus before any network isolation.
- ✗
Notify the Chief Information Security Officer (CISO) of the incident.
Why it's wrong here
Notifying the CISO is a required step in incident response, but it does not stop the active data exfiltration. The immediate priority per NIST is containment to minimize the impact of the incident; every moment spent on reporting before isolating the server allows the attacker to transfer more sensitive financial data. Notification should occur concurrently with or immediately after the containment action, not as a substitute for isolating the server at the switch level.
When this WOULD be correct
This would be correct as the immediate next step if the incident response procedure requires notification of the CISO before any containment actions, or if the analyst lacks authority to disconnect and must escalate first.
- ✗
Power off the server to prevent further damage.
Why it's wrong here
Powering off the server would prevent further file-level damage, but it is an overly aggressive action that sacrifices volatile forensic data. Memory contents, active network connections, running malicious processes, and unencrypted data in RAM are all lost on shutdown, severely hampering the investigation. In a financial incident, you should use logical network isolation at the switch first to contain the threat while preserving the system state, unless there is an immediate physical safety hazard.
When this WOULD be correct
In a scenario where a server is experiencing a destructive malware infection (e.g., ransomware encrypting files) and there is no need for forensic preservation, powering off can prevent further damage. For example, if a server is rapidly deleting critical data and network isolation is insufficient, power-off may be warranted.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Disconnect the server from the network at the switch level.Correct answer▾
Why this is correct
Isolating the server at the switch port is the proper containment step because it severs the network path used for data exfiltration without disrupting the host's power or volatile memory. This preserves running processes, open network connections, and other live forensic evidence, aligning with the NIST incident response framework's containment phase. It immediately halts the unauthorized data transfer while allowing the analyst to gather evidence from the live system.
✗Run a comprehensive antivirus scan on the server.Wrong answer — click to see why▾
Why this is wrong here
Running a comprehensive antivirus scan is a time-consuming step that delays containment. In this scenario, the immediate priority is to stop the data exfiltration by disconnecting the server from the network, not to analyze the malware.
★ When this WOULD be the correct answer
This would be correct if the question described a suspected malware infection on a non-critical system with no signs of active data exfiltration, and the incident response procedure required initial triage with antivirus before any network isolation.
Why candidates choose this
Candidates often default to scanning for malware as a first step, not realizing that containment (disconnection) takes precedence when there is clear evidence of ongoing data exfiltration.
✗Notify the Chief Information Security Officer (CISO) of the incident.Wrong answer — click to see why▾
Why this is wrong here
In this scenario, the immediate priority is containment to prevent data exfiltration. Notifying the CISO is a later step after containment and initial analysis, not the immediate next action.
★ When this WOULD be the correct answer
This would be correct as the immediate next step if the incident response procedure requires notification of the CISO before any containment actions, or if the analyst lacks authority to disconnect and must escalate first.
Why candidates choose this
Candidates may think that escalation is always the first step in incident response, but containment takes precedence when active data exfiltration is suspected.
✗Power off the server to prevent further damage.Wrong answer — click to see why▾
Why this is wrong here
Powering off the server would destroy volatile evidence (e.g., memory contents, active network connections) and may not stop data exfiltration if the attacker has persistence. The immediate priority is containment via network isolation, not power-off.
★ When this WOULD be the correct answer
In a scenario where a server is experiencing a destructive malware infection (e.g., ransomware encrypting files) and there is no need for forensic preservation, powering off can prevent further damage. For example, if a server is rapidly deleting critical data and network isolation is insufficient, power-off may be warranted.
Why candidates choose this
Candidates may think that stopping the server entirely is the fastest way to halt malicious activity, overlooking the importance of preserving evidence and the fact that network isolation achieves containment without losing volatile data.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Switch
A switch is a networking device that connects devices on a local area network and uses MAC addresses to forward data only to the intended recipient.
Key term
VLAN
A VLAN (Virtual Local Area Network) is a logical grouping of network devices that behave as if they are on the same physical network segment, regardless of their actual physical location.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.