SY0-701 Security Operations Practice Question
A security analyst at a financial firm notices a significant increase in DNS queries from an internal server to a rarely visited external domain. The queries are for unusual subdomain names that contain encoded data. The server is not a DNS server and does not typically generate outbound traffic. Which of the following is the MOST appropriate immediate action for the analyst to take?
⚠ Common exam trap
Many candidates choose to log or scan first, mistaking detection for containment, but the SY0-701 emphasizes immediate isolation to stop data loss in active exfiltration scenarios.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the server from the network to prevent further data loss.
The server is exhibiting signs of a DNS data exfiltration attack, where encoded data is being tunneled through DNS queries to an external domain. Isolating the server immediately stops the data loss and prevents further compromise, which is the most critical first step in incident response. Blocking traffic or scanning alone would not halt the active exfiltration, and logging without action allows continued data theft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block all outbound DNS traffic from the server immediately.
Why it's wrong here
Blocking all DNS traffic may prevent legitimate services that rely on name resolution, and it does not address the underlying compromise. Attackers could also use alternative exfiltration methods. This action is too broad and does not follow the containment-first principle.
When this WOULD be correct
If the question stated that the server is critical and cannot be isolated, and the analyst has confirmed that blocking DNS will not affect business operations, then blocking DNS queries would be appropriate to stop ongoing data exfiltration.
- ✓
Isolate the server from the network to prevent further data loss.
Why this is correct
Isolation effectively stops the ongoing DNS tunneling by severing the server’s network connectivity. This contains the incident, prevents additional data exfiltration, and provides a controlled environment for further forensic analysis. It aligns with standard incident response procedures.
- ✗
Create a firewall rule to log all further DNS queries from the server.
Why it's wrong here
Logging queries provides visibility for forensic investigation but fails to stop the active data exfiltration occurring via DNS tunneling. This action is useful during a post-incident review or when monitoring suspicious traffic patterns without wanting to disrupt legitimate business processes. In this scenario, however, the analyst must prioritise containment by isolating the server or blocking the malicious domain to prevent further loss of sensitive financial information.
When this WOULD be correct
This option would be correct in a scenario where the analyst needs to gather forensic evidence of suspicious activity without disrupting operations, such as when investigating a low-priority anomaly that does not indicate an active breach, and the server is not critical to immediate security.
- ✗
Run an antivirus scan on the server.
Why it's wrong here
Antivirus scans may detect known malware, but DNS tunneling tools are often custom or fileless and may bypass traditional signatures. Moreover, scanning is a lengthy process that does not immediately halt the exfiltration. Containment should come before remediation.
When this WOULD be correct
An antivirus scan would be the most appropriate immediate action if the question described a user reporting a slow computer with pop-ups and unknown processes, and the goal is to identify and remove malware without network disruption.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Isolate the server from the network to prevent further data loss.Correct answer▾
Why this is correct
Isolation effectively stops the ongoing DNS tunneling by severing the server’s network connectivity. This contains the incident, prevents additional data exfiltration, and provides a controlled environment for further forensic analysis. It aligns with standard incident response procedures.
✗Block all outbound DNS traffic from the server immediately.Wrong answer — click to see why▾
Why this is wrong here
Blocking all outbound DNS traffic immediately could disrupt legitimate services and does not address the potential data exfiltration already occurring; isolation is preferred to stop the threat without impacting other systems.
★ When this WOULD be the correct answer
If the question stated that the server is critical and cannot be isolated, and the analyst has confirmed that blocking DNS will not affect business operations, then blocking DNS queries would be appropriate to stop ongoing data exfiltration.
Why candidates choose this
Candidates may think blocking the suspicious traffic is a quick fix, but they overlook the need to contain the threat first and avoid collateral damage to other services.
✗Create a firewall rule to log all further DNS queries from the server.Wrong answer — click to see why▾
Why this is wrong here
Creating a firewall rule to log further DNS queries is a passive monitoring step that does not immediately stop the potential data exfiltration or compromise. Given the evidence of encoded data in DNS queries, the priority is to contain the threat by isolating the server, not just logging additional activity.
★ When this WOULD be the correct answer
This option would be correct in a scenario where the analyst needs to gather forensic evidence of suspicious activity without disrupting operations, such as when investigating a low-priority anomaly that does not indicate an active breach, and the server is not critical to immediate security.
Why candidates choose this
Candidates may choose this because logging seems like a safe, non-disruptive step that preserves evidence, but they overlook the urgency of stopping potential data exfiltration indicated by encoded DNS queries.
✗Run an antivirus scan on the server.Wrong answer — click to see why▾
Why this is wrong here
Running an antivirus scan is a reactive, slower step that does not immediately stop potential data exfiltration via DNS tunneling. The server is already compromised and actively sending data, so isolation is needed first.
★ When this WOULD be the correct answer
An antivirus scan would be the most appropriate immediate action if the question described a user reporting a slow computer with pop-ups and unknown processes, and the goal is to identify and remove malware without network disruption.
Why candidates choose this
Candidates often default to antivirus as a standard response to any security incident, overlooking the urgency of stopping active data exfiltration in this specific scenario.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.