Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A security analyst at a financial firm detects an unusual spike in outbound network traffic from a database server that normally only communicates with internal web servers. The traffic is directed to numerous external IP addresses in various countries. According to established incident response procedures, what should be the analyst's immediate next step?

⚠ Common exam trap

Test-takers frequently confuse 'immediate containment' with 'immediate notification' or 'immediate remediation,' but the SY0-701 incident response framework prioritizes stopping the active threat (containment) over escalation or scanning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disconnect the server from the network at the switch level.

Disconnecting the server at the switch level (e.g., shutting down the switch port or placing it in a quarantine VLAN) is the immediate containment step per incident response procedures. This stops the outbound data exfiltration without risking data loss or corruption that could occur from a hard power-off, and it preserves volatile memory evidence for forensic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disconnect the server from the network at the switch level.

    Why this is correct

    Isolating the server at the switch port is the proper containment step because it severs the network path used for data exfiltration without disrupting the host's power or volatile memory. This preserves running processes, open network connections, and other live forensic evidence, aligning with the NIST incident response framework's containment phase. It immediately halts the unauthorized data transfer while allowing the analyst to gather evidence from the live system.

  • Run a comprehensive antivirus scan on the server.

    Why it's wrong here

    A comprehensive antivirus scan is a detection and eradication activity, not a containment measure. During the scan, the server remains connected to the network, so the data exfiltration continues unabated, and the scan's intensive I/O activity may trigger malware countermeasures that destroy volatile evidence. Prioritizing the scan over containment delays the critical action of stopping the breach and may alert the attacker, worsening the incident.

    When this WOULD be correct

    This would be correct if the question described a suspected malware infection on a non-critical system with no signs of active data exfiltration, and the incident response procedure required initial triage with antivirus before any network isolation.

  • Notify the Chief Information Security Officer (CISO) of the incident.

    Why it's wrong here

    Notifying the CISO is a required step in incident response, but it does not stop the active data exfiltration. The immediate priority per NIST is containment to minimize the impact of the incident; every moment spent on reporting before isolating the server allows the attacker to transfer more sensitive financial data. Notification should occur concurrently with or immediately after the containment action, not as a substitute for isolating the server at the switch level.

    When this WOULD be correct

    This would be correct as the immediate next step if the incident response procedure requires notification of the CISO before any containment actions, or if the analyst lacks authority to disconnect and must escalate first.

  • Power off the server to prevent further damage.

    Why it's wrong here

    Powering off the server would prevent further file-level damage, but it is an overly aggressive action that sacrifices volatile forensic data. Memory contents, active network connections, running malicious processes, and unencrypted data in RAM are all lost on shutdown, severely hampering the investigation. In a financial incident, you should use logical network isolation at the switch first to contain the threat while preserving the system state, unless there is an immediate physical safety hazard.

    When this WOULD be correct

    In a scenario where a server is experiencing a destructive malware infection (e.g., ransomware encrypting files) and there is no need for forensic preservation, powering off can prevent further damage. For example, if a server is rapidly deleting critical data and network isolation is insufficient, power-off may be warranted.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Disconnect the server from the network at the switch level.Correct answer

Why this is correct

Isolating the server at the switch port is the proper containment step because it severs the network path used for data exfiltration without disrupting the host's power or volatile memory. This preserves running processes, open network connections, and other live forensic evidence, aligning with the NIST incident response framework's containment phase. It immediately halts the unauthorized data transfer while allowing the analyst to gather evidence from the live system.

Run a comprehensive antivirus scan on the server.Wrong answer — click to see why

Why this is wrong here

Running a comprehensive antivirus scan is a time-consuming step that delays containment. In this scenario, the immediate priority is to stop the data exfiltration by disconnecting the server from the network, not to analyze the malware.

★ When this WOULD be the correct answer

This would be correct if the question described a suspected malware infection on a non-critical system with no signs of active data exfiltration, and the incident response procedure required initial triage with antivirus before any network isolation.

Why candidates choose this

Candidates often default to scanning for malware as a first step, not realizing that containment (disconnection) takes precedence when there is clear evidence of ongoing data exfiltration.

Notify the Chief Information Security Officer (CISO) of the incident.Wrong answer — click to see why

Why this is wrong here

In this scenario, the immediate priority is containment to prevent data exfiltration. Notifying the CISO is a later step after containment and initial analysis, not the immediate next action.

★ When this WOULD be the correct answer

This would be correct as the immediate next step if the incident response procedure requires notification of the CISO before any containment actions, or if the analyst lacks authority to disconnect and must escalate first.

Why candidates choose this

Candidates may think that escalation is always the first step in incident response, but containment takes precedence when active data exfiltration is suspected.

Power off the server to prevent further damage.Wrong answer — click to see why

Why this is wrong here

Powering off the server would destroy volatile evidence (e.g., memory contents, active network connections) and may not stop data exfiltration if the attacker has persistence. The immediate priority is containment via network isolation, not power-off.

★ When this WOULD be the correct answer

In a scenario where a server is experiencing a destructive malware infection (e.g., ransomware encrypting files) and there is no need for forensic preservation, powering off can prevent further damage. For example, if a server is rapidly deleting critical data and network isolation is insufficient, power-off may be warranted.

Why candidates choose this

Candidates may think that stopping the server entirely is the fastest way to halt malicious activity, overlooking the importance of preserving evidence and the fact that network isolation achieves containment without losing volatile data.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.