SY0-701 Security Operations Practice Question
A security analyst detects unusual outbound traffic from a workstation that appears to be communicating with a known malicious IP address. The analyst immediately isolates the workstation from the network. Which of the following is the NEXT step in the incident response process according to NIST SP 800-61?
⚠ Common exam trap
It's easy for candidates to confuse 'Containment' with the final isolation step, forgetting that NIST mandates a separate Eradication phase to eliminate the threat before recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Eradication
According to NIST SP 800-61, the incident response process follows a sequence: Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Lessons Learned. Since the analyst has already performed containment by isolating the workstation, the next step is Eradication, which involves removing the threat (e.g., malware, backdoors) from the affected system. This ensures the root cause is eliminated before moving to recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Eradication
Why this is correct
Eradication is the correct immediate next step after containment. The analyst must identify and eliminate the root cause of the malicious outbound traffic—such as removing malware binaries, terminating adversary-controlled processes, deleting persistence mechanisms like scheduled tasks or registry run keys, and revoking compromised credentials. Isolation alone only limits the threat's spread; without eradication, the infection remains dormant and can easily reinfect the host once reconnected.
- ✗
Recovery
Why it's wrong here
Recovery restores the isolated system to normal operation, but it must only begin after eradication has verified that the system is clean. Attempting recovery prematurely—while malicious artifacts or backdoors remain—would likely result in reinfection and could re-establish the outbound traffic. The correct sequence is to finish eradication first, then move to recovery, which may involve rebuilding, patching, and validating system integrity before returning to production.
When this WOULD be correct
Recovery would be the next step after eradication in a scenario where the threat has already been removed (e.g., malware cleaned) and the question asks for the step to restore the system to production.
- ✗
Containment
Why it's wrong here
Containment is a prior phase that has already been executed by isolating the affected workstation. Repeating containment would be redundant and would delay the progression to eradication, which is necessary to address the underlying compromise. Containment's goal is to stop the spread and limit damage, but it does not remove the threat from the system, so it cannot be the next logical step in this scenario.
When this WOULD be correct
A question asks: 'After detecting a malware outbreak, what is the first step to prevent further spread?' Containment would be correct because it focuses on limiting damage before eradication or recovery.
- ✗
Lessons Learned
Why it's wrong here
Lessons Learned is the final phase of the incident response lifecycle, conducted after eradication and recovery have restored normal operations. This phase involves a formal post-incident review, root-cause analysis, and the development of recommendations to improve future response, such as updating playbooks or enhancing detection rules. Skipping directly to Lessons Learned before eradicating the threat would leave the organization exposed and prevent the immediate remediation that is critical at this stage.
When this WOULD be correct
Lessons Learned would be the correct answer if the question asked for the final step in the incident response process after recovery is complete, or if the scenario described that the incident has been fully resolved and the team is now conducting a post-incident review to improve future responses.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓EradicationCorrect answer▾
Why this is correct
Eradication is the correct immediate next step after containment. The analyst must identify and eliminate the root cause of the malicious outbound traffic—such as removing malware binaries, terminating adversary-controlled processes, deleting persistence mechanisms like scheduled tasks or registry run keys, and revoking compromised credentials. Isolation alone only limits the threat's spread; without eradication, the infection remains dormant and can easily reinfect the host once reconnected.
✗RecoveryWrong answer — click to see why▾
Why this is wrong here
Recovery occurs after eradication and involves restoring systems to normal operation. Since the workstation has only been isolated (containment), eradication—removing the threat—must come next.
★ When this WOULD be the correct answer
Recovery would be the next step after eradication in a scenario where the threat has already been removed (e.g., malware cleaned) and the question asks for the step to restore the system to production.
Why candidates choose this
Candidates may confuse the order of steps, thinking that recovery immediately follows containment, or they may misinterpret 'recovery' as a broad term that includes threat removal.
✗ContainmentWrong answer — click to see why▾
Why this is wrong here
In NIST SP 800-61, containment is performed before eradication. The question states the workstation has already been isolated (containment), so the next step is eradication, not containment.
★ When this WOULD be the correct answer
A question asks: 'After detecting a malware outbreak, what is the first step to prevent further spread?' Containment would be correct because it focuses on limiting damage before eradication or recovery.
Why candidates choose this
Candidates may confuse containment with isolation, thinking that isolating the workstation is the containment step, but the question explicitly says isolation has already occurred, making containment the prior step, not the next.
✗Lessons LearnedWrong answer — click to see why▾
Why this is wrong here
In NIST SP 800-61, the incident response process follows: Preparation, Detection & Analysis, Containment, Eradication, Recovery, and Post-Incident Activity (Lessons Learned). After containment (isolating the workstation), the next step is Eradication, not Lessons Learned. Lessons Learned occurs after Recovery.
★ When this WOULD be the correct answer
Lessons Learned would be the correct answer if the question asked for the final step in the incident response process after recovery is complete, or if the scenario described that the incident has been fully resolved and the team is now conducting a post-incident review to improve future responses.
Why candidates choose this
Candidates may think that after isolating the workstation, the next logical step is to analyze what happened and learn from it, confusing the order of steps or skipping eradication and recovery.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.