Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A security analyst at a financial firm notices a significant increase in DNS queries from an internal server to a rarely visited external domain. The queries are for unusual subdomain names that contain encoded data. The server is not a DNS server and does not typically generate outbound traffic. Which of the following is the MOST appropriate immediate action for the analyst to take?

⚠ Common exam trap

Many candidates choose to log or scan first, mistaking detection for containment, but the SY0-701 emphasizes immediate isolation to stop data loss in active exfiltration scenarios.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate the server from the network to prevent further data loss.

The server is exhibiting signs of a DNS data exfiltration attack, where encoded data is being tunneled through DNS queries to an external domain. Isolating the server immediately stops the data loss and prevents further compromise, which is the most critical first step in incident response. Blocking traffic or scanning alone would not halt the active exfiltration, and logging without action allows continued data theft.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Block all outbound DNS traffic from the server immediately.

    Why it's wrong here

    Blocking all DNS traffic may prevent legitimate services that rely on name resolution, and it does not address the underlying compromise. Attackers could also use alternative exfiltration methods. This action is too broad and does not follow the containment-first principle.

    When this WOULD be correct

    If the question stated that the server is critical and cannot be isolated, and the analyst has confirmed that blocking DNS will not affect business operations, then blocking DNS queries would be appropriate to stop ongoing data exfiltration.

  • Isolate the server from the network to prevent further data loss.

    Why this is correct

    Isolation effectively stops the ongoing DNS tunneling by severing the server’s network connectivity. This contains the incident, prevents additional data exfiltration, and provides a controlled environment for further forensic analysis. It aligns with standard incident response procedures.

  • Create a firewall rule to log all further DNS queries from the server.

    Why it's wrong here

    Logging queries provides visibility for forensic investigation but fails to stop the active data exfiltration occurring via DNS tunneling. This action is useful during a post-incident review or when monitoring suspicious traffic patterns without wanting to disrupt legitimate business processes. In this scenario, however, the analyst must prioritise containment by isolating the server or blocking the malicious domain to prevent further loss of sensitive financial information.

    When this WOULD be correct

    This option would be correct in a scenario where the analyst needs to gather forensic evidence of suspicious activity without disrupting operations, such as when investigating a low-priority anomaly that does not indicate an active breach, and the server is not critical to immediate security.

  • Run an antivirus scan on the server.

    Why it's wrong here

    Antivirus scans may detect known malware, but DNS tunneling tools are often custom or fileless and may bypass traditional signatures. Moreover, scanning is a lengthy process that does not immediately halt the exfiltration. Containment should come before remediation.

    When this WOULD be correct

    An antivirus scan would be the most appropriate immediate action if the question described a user reporting a slow computer with pop-ups and unknown processes, and the goal is to identify and remove malware without network disruption.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Isolate the server from the network to prevent further data loss.Correct answer

Why this is correct

Isolation effectively stops the ongoing DNS tunneling by severing the server’s network connectivity. This contains the incident, prevents additional data exfiltration, and provides a controlled environment for further forensic analysis. It aligns with standard incident response procedures.

Block all outbound DNS traffic from the server immediately.Wrong answer — click to see why

Why this is wrong here

Blocking all outbound DNS traffic immediately could disrupt legitimate services and does not address the potential data exfiltration already occurring; isolation is preferred to stop the threat without impacting other systems.

★ When this WOULD be the correct answer

If the question stated that the server is critical and cannot be isolated, and the analyst has confirmed that blocking DNS will not affect business operations, then blocking DNS queries would be appropriate to stop ongoing data exfiltration.

Why candidates choose this

Candidates may think blocking the suspicious traffic is a quick fix, but they overlook the need to contain the threat first and avoid collateral damage to other services.

Create a firewall rule to log all further DNS queries from the server.Wrong answer — click to see why

Why this is wrong here

Creating a firewall rule to log further DNS queries is a passive monitoring step that does not immediately stop the potential data exfiltration or compromise. Given the evidence of encoded data in DNS queries, the priority is to contain the threat by isolating the server, not just logging additional activity.

★ When this WOULD be the correct answer

This option would be correct in a scenario where the analyst needs to gather forensic evidence of suspicious activity without disrupting operations, such as when investigating a low-priority anomaly that does not indicate an active breach, and the server is not critical to immediate security.

Why candidates choose this

Candidates may choose this because logging seems like a safe, non-disruptive step that preserves evidence, but they overlook the urgency of stopping potential data exfiltration indicated by encoded DNS queries.

Run an antivirus scan on the server.Wrong answer — click to see why

Why this is wrong here

Running an antivirus scan is a reactive, slower step that does not immediately stop potential data exfiltration via DNS tunneling. The server is already compromised and actively sending data, so isolation is needed first.

★ When this WOULD be the correct answer

An antivirus scan would be the most appropriate immediate action if the question described a user reporting a slow computer with pop-ups and unknown processes, and the goal is to identify and remove malware without network disruption.

Why candidates choose this

Candidates often default to antivirus as a standard response to any security incident, overlooking the urgency of stopping active data exfiltration in this specific scenario.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.