Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A security analyst detects unusual outbound traffic from a workstation to an external IP address known for command and control. The analyst has verified the alert and wants to contain the threat. According to the NIST SP 800-61 incident response process, which of the following steps should the analyst take FIRST?

⚠ Common exam trap

Watch out — candidates often confuse the order of incident response phases, choosing forensic analysis (Option B) first instead of containment, because they mistakenly believe evidence preservation must precede network isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disconnect the workstation from the network

According to NIST SP 800-61, the first step in containment during incident response is to prevent further damage by isolating the compromised system. Disconnecting the workstation from the network immediately stops the outbound command-and-control traffic, preventing data exfiltration and further compromise. This aligns with the 'containment' phase before any analysis or remediation occurs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disconnect the workstation from the network

    Why this is correct

    Disconnecting the workstation from the network cable or disabling its virtual NIC is the immediate containment action that stops active command-and-control beaconing and prevents further data exfiltration to the threat actor. Per NIST SP 800-61, this is the first priority once an incident is confirmed, as it isolates the compromised host and blocks lateral movement while preserving the current system state for later forensic acquisition. Do not delay this step for analysis or notification.

  • Perform a forensic analysis of the workstation

    Why it's wrong here

    Conducting forensic analysis on the live, still-connected system risks altering or losing volatile evidence as the ongoing malicious activity continues, and the adversary may detect the investigation and trigger a counter-forensic response. The proper sequence is to contain first, typically by disconnect, then acquire memory and disk images in a forensically sound manner, and only then analyze the copies offline. Analyzing before containment does not halt the exfiltration or lateral movement, so it is not the correct first action.

    When this WOULD be correct

    If the question asked 'After containing the threat, which step should the analyst take next?' or 'Which step is part of the eradication and recovery phase?', then forensic analysis would be correct to determine the root cause and scope.

  • Reimage the workstation

    Why it's wrong here

    Reimaging the workstation by reinstalling the OS wipes the disk and destroys critical forensic evidence, including malware artifacts, persistence mechanisms, and timestamps, which are essential for identifying the attack vector. It is an eradication and recovery step that should be performed only after containment and evidence collection, per the NIST incident response lifecycle. Moreover, reimaging does not stop the adversary if they have already moved laterally to other systems or established other persistence paths.

    When this WOULD be correct

    A question asks: 'After containing a compromised workstation and completing forensic analysis, which step should be taken to ensure the system is clean and can be returned to production?' In that scenario, reimaging would be correct as part of eradication and recovery.

  • Alert the system administrator

    Why it's wrong here

    Notifying the system administrator is an essential communication step in the incident response process, but it is not a technical containment action and does not immediately stop the ongoing network activity. The analyst can send an alert or call the admin while simultaneously disconnecting the host, but the priority must be to cut the network path. Alerting alone leaves the workstation online and the attacker free to continue exfiltration, so it is insufficient as the initial decision.

    When this WOULD be correct

    This would be correct if the question asked for the first step after containment is complete, or if the incident requires notification before any technical actions due to policy (e.g., legal or regulatory requirements).

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Disconnect the workstation from the networkCorrect answer

Why this is correct

Disconnecting the workstation from the network cable or disabling its virtual NIC is the immediate containment action that stops active command-and-control beaconing and prevents further data exfiltration to the threat actor. Per NIST SP 800-61, this is the first priority once an incident is confirmed, as it isolates the compromised host and blocks lateral movement while preserving the current system state for later forensic acquisition. Do not delay this step for analysis or notification.

Perform a forensic analysis of the workstationWrong answer — click to see why

Why this is wrong here

Per NIST SP 800-61, containment is the immediate priority after verification. Forensic analysis occurs after containment to preserve evidence and avoid altering the system state.

★ When this WOULD be the correct answer

If the question asked 'After containing the threat, which step should the analyst take next?' or 'Which step is part of the eradication and recovery phase?', then forensic analysis would be correct to determine the root cause and scope.

Why candidates choose this

Candidates may think forensic analysis is needed first to understand the threat, but NIST emphasizes containment before investigation to prevent further damage.

Reimage the workstationWrong answer — click to see why

Why this is wrong here

Reimaging the workstation is a recovery step, not a containment step. According to NIST SP 800-61, containment should occur before eradication or recovery to prevent further damage.

★ When this WOULD be the correct answer

A question asks: 'After containing a compromised workstation and completing forensic analysis, which step should be taken to ensure the system is clean and can be returned to production?' In that scenario, reimaging would be correct as part of eradication and recovery.

Why candidates choose this

Candidates may confuse containment with eradication, thinking that removing the malware immediately via reimage is the first step, but containment (disconnecting) must come first to stop the threat from spreading.

Alert the system administratorWrong answer — click to see why

Why this is wrong here

Alerting the system administrator is not the first containment step; NIST SP 800-61 prioritizes immediate containment actions like disconnecting the workstation to prevent further C2 communication.

★ When this WOULD be the correct answer

This would be correct if the question asked for the first step after containment is complete, or if the incident requires notification before any technical actions due to policy (e.g., legal or regulatory requirements).

Why candidates choose this

Candidates may think notifying a supervisor or administrator is always the first step in incident response, confusing communication protocols with technical containment priorities.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.