Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A security analyst in a SOC receives an alert indicating that a large volume of data was transferred from a user's workstation to an external IP address at 2:00 AM. The analyst suspects a data exfiltration attack. According to incident response best practices, what should the analyst do FIRST?

⚠ Common exam trap

The trap here is that candidates often jump to immediate containment (blocking the IP) or recovery (restoring from backup) without first verifying the alert through log analysis, which is a fundamental incident response principle emphasized in the SY0-701 exam.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Review the user's login and activity logs.

In incident response, the first step is to gather evidence and understand the scope of the incident. Reviewing the user's login and activity logs (e.g., Windows Event Logs, authentication logs, and process creation logs) allows the analyst to verify if the user was actually logged in at 2:00 AM, identify any anomalous behavior (e.g., use of unauthorized tools or unusual file access patterns), and determine whether the data transfer was initiated by the user or by malware. This aligns with the NIST SP 800-61 incident response lifecycle, specifically the identification and analysis phase, where initial triage focuses on log review before taking containment actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Block the external IP address at the firewall.

    Why it's wrong here

    Blocking the IP is a containment action, but it should be taken after confirming the incident and assessing potential impact. Doing it first might disrupt legitimate services and does not help in gathering initial evidence.

    When this WOULD be correct

    This option would be correct if the question stated that the analyst has already confirmed the data exfiltration is occurring in real-time and immediate containment is required to prevent further data loss, such as in a scenario where the alert is verified and the external IP is known malicious.

  • Review the user's login and activity logs.

    Why this is correct

    Reviewing logs is the correct first step. It allows the analyst to verify the alert, see if the user was logged in, identify the process responsible for the transfer, and gather details necessary for informed decision-making.

  • Contact the user to inquire about the transfer.

    Why it's wrong here

    Directly contacting the user to ask about the transfer risks tipping off a potential insider threat, alerting them to the active investigation and giving them an opportunity to destroy additional evidence or escalate their access. User recollections are also inherently unreliable and may be inaccurate or intentionally misleading, so technical logs from authentication, endpoint, and data loss prevention systems should be reviewed first. Premature communication can compromise the integrity of the response and should be delayed until the analyst has established a factual baseline from evidence.

    When this WOULD be correct

    If the question stated that the transfer was flagged during business hours and the user is available, and the analyst needs to quickly verify if the transfer was authorized (e.g., a legitimate large file upload), then contacting the user first would be appropriate to avoid unnecessary escalation.

  • Restore the workstation from a known good backup.

    Why it's wrong here

    Restoring the workstation from a known good backup is an inappropriate first response because it will overwrite the current disk state, destroying volatile forensic evidence such as memory artifacts, open network connections, and event logs that are critical for understanding the scope of the transfer. Additionally, if the backup predates a persistent threat or is itself compromised, the restoration could reintroduce or fail to remove the malicious activity. Recovery actions like this should only be performed after a thorough investigation and containment, ensuring evidence preservation and accurate incident scoping.

    When this WOULD be correct

    If the question stated that the workstation was confirmed compromised (e.g., via forensic analysis) and the priority is to remove malware and restore normal operations, then restoring from a known good backup would be the correct first step.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Review the user's login and activity logs.Correct answer

Why this is correct

Reviewing logs is the correct first step. It allows the analyst to verify the alert, see if the user was logged in, identify the process responsible for the transfer, and gather details necessary for informed decision-making.

Block the external IP address at the firewall.Wrong answer — click to see why

Why this is wrong here

Blocking the external IP at the firewall is a containment step that should be taken after verifying the alert is a true positive. The first step is to gather more information to confirm the incident, not to take immediate action that could disrupt legitimate traffic.

★ When this WOULD be the correct answer

This option would be correct if the question stated that the analyst has already confirmed the data exfiltration is occurring in real-time and immediate containment is required to prevent further data loss, such as in a scenario where the alert is verified and the external IP is known malicious.

Why candidates choose this

Candidates may think that stopping the data transfer immediately is the top priority, but they overlook the need for verification first, as per incident response frameworks like NIST SP 800-61.

Contact the user to inquire about the transfer.Wrong answer — click to see why

Why this is wrong here

Contacting the user immediately may alert a potential insider threat or disrupt forensic preservation; the analyst should first gather objective evidence from logs to confirm the incident before involving personnel.

★ When this WOULD be the correct answer

If the question stated that the transfer was flagged during business hours and the user is available, and the analyst needs to quickly verify if the transfer was authorized (e.g., a legitimate large file upload), then contacting the user first would be appropriate to avoid unnecessary escalation.

Why candidates choose this

Candidates often think that asking the user is the fastest way to clarify the situation, but they overlook the risk of tipping off a malicious insider and the need for evidence-based investigation first.

Restore the workstation from a known good backup.Wrong answer — click to see why

Why this is wrong here

Restoring from backup is a containment/recovery step that occurs after the incident has been confirmed and analyzed; it is premature before verifying the alert and gathering evidence.

★ When this WOULD be the correct answer

If the question stated that the workstation was confirmed compromised (e.g., via forensic analysis) and the priority is to remove malware and restore normal operations, then restoring from a known good backup would be the correct first step.

Why candidates choose this

Candidates may think that restoring from backup quickly stops data loss and removes any malicious software, but they overlook the need to first confirm the incident and preserve evidence.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.