SY0-701 Security Operations Practice Question
A security analyst detects repeated outbound traffic from a single workstation to an IP address listed on a public threat intelligence feed as a known command-and-control server. The user reports that the workstation is behaving slowly and that antivirus software is up to date. According to incident response best practices, what should the analyst do FIRST?
⚠ Common exam trap
A common mix-up: candidates choose to gather more evidence (Option D) or run a scan (Option B) first, forgetting that containment is the immediate priority once a live C2 connection is confirmed, per the NIST SP 800-61 incident response lifecycle.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the workstation from the network
The correct first step is to disconnect the workstation from the network to immediately contain the threat and prevent further command-and-control (C2) communication. Since the traffic is already confirmed to a known C2 server via a public threat intelligence feed, the priority is to stop data exfiltration and potential lateral movement, not to gather more evidence or notify the user. Incident response best practices emphasize containment before eradication or notification to minimize damage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disconnect the workstation from the network
Why this is correct
Disconnecting the workstation from the network—by unplugging the Ethernet cable, turning off Wi-Fi, or deactivating the virtual NIC—stops the observed outbound traffic instantly. This containment step severs the command-and-control channel and aborts any ongoing data exfiltration, which is the immediate priority in incident response. It also prevents the malicious process from spreading laterally to other systems on the same segment. While this may lose some volatile network connections, the value of halting the threat outweighs forensic collection at this stage.
- ✗
Run a full antivirus scan on the workstation
Why it's wrong here
Running a full antivirus scan is not a containment action; it only inspects files already on disk and does nothing to interrupt the live network connection that is exfiltrating data. Modern malware can evade signature-based scanners, especially if it is polymorphic or zero-day, so the scan may come back clean even while the machine remains compromised. Furthermore, the scan itself consumes significant CPU and I/O resources, and every minute spent scanning allows the attacker to continue sending sensitive data to the remote host. The correct sequence is to isolate the host first, then run the scan as part of the eradication phase.
When this WOULD be correct
This would be correct if the question stated that the antivirus was not up to date and the analyst had already verified the traffic as suspicious but not yet confirmed malicious, making a scan the next logical step before escalation.
- ✗
Notify the user that their workstation may be compromised
Why it's wrong here
Notifying the user before containment is risky because it can alert an insider who is complicit, or cause an innocent user to log out, close programs, or reboot the machine, which may destroy volatile memory evidence that would be critical for later forensic analysis. It also adds a human interaction delay to a technically urgent situation, leaving the malicious outbound connection active. Incident response policies typically require the analyst to contain the threat first and inform the user after the network connection has been severed, ideally through the proper management channel to avoid compromising the investigation.
When this WOULD be correct
In a scenario where the analyst has already contained the threat (e.g., disconnected the workstation) and needs to inform the user about the incident and next steps, such as for an interview or data collection, notifying the user would be appropriate.
- ✗
Check the firewall logs to confirm the destination IP
Why it's wrong here
Checking the firewall logs to confirm the destination IP is a legitimate investigative step, but performing it before containment leaves the workstation actively communicating with the attacker, so the ongoing exfiltration continues while the analyst works. Log analysis takes time and may not reveal the full context of what the malicious process is sending; it only tells you the destination, not the content. Additionally, the attacker may be actively monitoring the session and could take countermeasures such as deleting logs or escalating privileges on other machines. Containment should always precede detailed log review; once the host is isolated, the analyst can safely examine logs without the clock ticking on data loss.
When this WOULD be correct
If the question asked for the first step after containment (e.g., 'After disconnecting the workstation, what should the analyst do next?'), then checking firewall logs to gather evidence and confirm the threat would be appropriate.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Disconnect the workstation from the networkCorrect answer▾
Why this is correct
Disconnecting the workstation from the network—by unplugging the Ethernet cable, turning off Wi-Fi, or deactivating the virtual NIC—stops the observed outbound traffic instantly. This containment step severs the command-and-control channel and aborts any ongoing data exfiltration, which is the immediate priority in incident response. It also prevents the malicious process from spreading laterally to other systems on the same segment. While this may lose some volatile network connections, the value of halting the threat outweighs forensic collection at this stage.
✗Run a full antivirus scan on the workstationWrong answer — click to see why▾
Why this is wrong here
Running a full antivirus scan delays containment; the priority is to stop potential data exfiltration or lateral movement by immediately isolating the workstation from the network.
★ When this WOULD be the correct answer
This would be correct if the question stated that the antivirus was not up to date and the analyst had already verified the traffic as suspicious but not yet confirmed malicious, making a scan the next logical step before escalation.
Why candidates choose this
Candidates may assume antivirus is the primary defense and that scanning is the standard first response, overlooking the urgency of containing a confirmed C2 communication.
✗Notify the user that their workstation may be compromisedWrong answer — click to see why▾
Why this is wrong here
Notifying the user before containing the threat could cause panic or lead to the user taking actions that disrupt forensic evidence or further compromise the system. Incident response best practices prioritize containment (disconnecting the network) over communication.
★ When this WOULD be the correct answer
In a scenario where the analyst has already contained the threat (e.g., disconnected the workstation) and needs to inform the user about the incident and next steps, such as for an interview or data collection, notifying the user would be appropriate.
Why candidates choose this
Candidates may think that informing the user is a logical first step to gather information or warn them, but they overlook the immediate need to stop the command-and-control communication to prevent data exfiltration or further compromise.
✗Check the firewall logs to confirm the destination IPWrong answer — click to see why▾
Why this is wrong here
Checking firewall logs to confirm the destination IP is a secondary step; the priority is immediate containment by disconnecting the workstation to prevent further C2 communication.
★ When this WOULD be the correct answer
If the question asked for the first step after containment (e.g., 'After disconnecting the workstation, what should the analyst do next?'), then checking firewall logs to gather evidence and confirm the threat would be appropriate.
Why candidates choose this
Candidates may think verification is necessary before action, but in incident response, containment takes precedence over confirmation when a clear indicator of compromise exists.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.