Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A security analyst at a manufacturing company notices multiple workstations generating high volumes of encrypted outbound traffic and displaying ransom notes. The analyst suspects a ransomware outbreak. According to the incident response process, which of the following should the analyst perform FIRST?

⚠ Common exam trap

The trap here is that candidates often jump to eradication (wiping drives) or notification (calling law enforcement) first, forgetting that containment is the immediate priority to stop the outbreak from spreading across the network.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate the affected workstations from the network by disconnecting their network cables and disabling Wi-Fi.

The first priority in a suspected ransomware outbreak is containment to prevent lateral spread and further encryption. Disconnecting network cables and disabling Wi-Fi immediately isolates the affected workstations from the network, stopping the ransomware from communicating with its command-and-control (C2) server or encrypting additional systems. This aligns with the NIST SP 800-61 incident response lifecycle, where containment precedes eradication and recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Immediately wipe the hard drives of all affected workstations and reinstall the operating system.

    Why it's wrong here

    Immediately wiping the hard drives of affected workstations is inappropriate as a first action because it destroys all forensic evidence needed to identify the ransomware variant, the entry vector, and the attacker's tactics, techniques, and procedures (TTPs) for preventive measures. More critically, wiping does not address the root cause or stop the spread; if the ransomware has already moved to other hosts or network shares, erasing only the affected machines leaves the backdoor open and the infection could continue to propagate during the wipe and reinstallation process.

    When this WOULD be correct

    This would be correct if the question stated that the organization has already completed containment, eradication, and evidence preservation, and now needs to restore operations quickly to minimize downtime. For example: 'After isolating and analyzing the ransomware, which step should be taken to restore affected workstations?'

  • Isolate the affected workstations from the network by disconnecting their network cables and disabling Wi-Fi.

    Why this is correct

    Disconnecting the network cables and disabling Wi-Fi on affected workstations is the correct immediate step because it performs a logical and physical air-gap, severing all paths for the ransomware to communicate with its command-and-control server or move laterally to other hosts. This containment action stops the active encryption of SMB shares, database servers, and other network devices, while also preserving dynamic evidence such as memory and running processes for later analysis, which would be destroyed if the system were powered off.

  • Contact local law enforcement to report the ransomware incident and request a forensic investigation.

    Why it's wrong here

    Contacting law enforcement is a necessary post-incident notification step, but it is not a technical containment control and should never replace immediate isolation actions. Reporting the incident while the ransomware is still actively spreading could allow the attack to reach critical manufacturing systems, supervisory control and data acquisition (SCADA) networks, or other production assets before investigators arrive, and law enforcement will likely advise preserving evidence, which would still require the analyst to first isolate the infected workstations to stop the damage.

    When this WOULD be correct

    This would be correct if the question asked: 'After containing the ransomware outbreak and preserving evidence, which step should the analyst perform next?'

  • Conduct a full forensic analysis of one affected workstation to determine the ransomware variant and entry vector.

    Why it's wrong here

    Conducting a full forensic analysis before containing the incident is premature because the ransomware is still active and may be continuously encrypting files, deleting shadow copies, and propagating to other systems through admin shares or phishing email connections. Additionally, volatile evidence like memory contents and live network connections would be altered or lost during the prolonged analysis process, and the analyst's own forensic tools could trigger detection mechanisms or interfere with the malware's behavior, ultimately increasing the scope of the incident.

    When this WOULD be correct

    This option would be correct if the question stated that the affected workstations have already been isolated and the incident response team is now in the identification or analysis phase, needing to determine the ransomware variant and entry vector to guide eradication and recovery.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Isolate the affected workstations from the network by disconnecting their network cables and disabling Wi-Fi.Correct answer

Why this is correct

Disconnecting the network cables and disabling Wi-Fi on affected workstations is the correct immediate step because it performs a logical and physical air-gap, severing all paths for the ransomware to communicate with its command-and-control server or move laterally to other hosts. This containment action stops the active encryption of SMB shares, database servers, and other network devices, while also preserving dynamic evidence such as memory and running processes for later analysis, which would be destroyed if the system were powered off.

Immediately wipe the hard drives of all affected workstations and reinstall the operating system.Wrong answer — click to see why

Why this is wrong here

Wiping drives and reinstalling OS destroys volatile evidence and prevents forensic analysis to determine the ransomware variant and entry vector, which is critical for containment and eradication. The first step in incident response is containment, not eradication or recovery.

★ When this WOULD be the correct answer

This would be correct if the question stated that the organization has already completed containment, eradication, and evidence preservation, and now needs to restore operations quickly to minimize downtime. For example: 'After isolating and analyzing the ransomware, which step should be taken to restore affected workstations?'

Why candidates choose this

Candidates may think immediate eradication stops the ransomware spread, but they overlook the need for containment first and the importance of preserving evidence for investigation and legal action.

Contact local law enforcement to report the ransomware incident and request a forensic investigation.Wrong answer — click to see why

Why this is wrong here

Contacting law enforcement is not the first step; immediate containment (isolation) is required to prevent further spread of the ransomware across the network.

★ When this WOULD be the correct answer

This would be correct if the question asked: 'After containing the ransomware outbreak and preserving evidence, which step should the analyst perform next?'

Why candidates choose this

Candidates may believe that involving law enforcement early is critical for legal and forensic reasons, but they overlook the priority of containment in incident response.

Conduct a full forensic analysis of one affected workstation to determine the ransomware variant and entry vector.Wrong answer — click to see why

Why this is wrong here

In the incident response process, the first priority is containment to prevent further spread. Conducting a forensic analysis before containment allows the ransomware to continue encrypting other systems, violating the containment-first principle.

★ When this WOULD be the correct answer

This option would be correct if the question stated that the affected workstations have already been isolated and the incident response team is now in the identification or analysis phase, needing to determine the ransomware variant and entry vector to guide eradication and recovery.

Why candidates choose this

Candidates may think that understanding the ransomware variant is critical to stopping it, but they overlook that containment must occur first to prevent further damage.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.