Courseiva
Question 6 of 1,013
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A security analyst is responding to a potential ransomware incident on a Windows server that is still running. The analyst needs to preserve forensic evidence for analysis. Which of the following actions should the analyst perform first, based on the order of volatility?

⚠ Common exam trap

Watch out — candidates often think shutting down the server is the safest first step to contain damage, but CompTIA tests the forensic principle that volatile data must be preserved before any containment or remediation actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Capture a full memory dump of the server

The order of volatility dictates that the most volatile data (memory) must be captured first because it contains critical evidence like running processes, network connections, and encryption keys that will be lost when the system is powered off. A full memory dump preserves this volatile data before any other actions that could alter the system state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Capture a full memory dump of the server

    Why this is correct

    Correct. Memory is the most volatile data and should be captured first to preserve evidence such as running processes, network connections, and malware in memory. Any delay or system shutdown may cause this data to be lost.

  • Shut down the server to prevent further damage

    Why it's wrong here

    Shutting down the server is incorrect as the first response because a normal power-off clears RAM, deleting the very evidence needed to identify the ransomware strain and recover encryption keys. It also risks triggering anti-forensic payloads that some malware executes upon shutdown, potentially wiping remnants or causing further encryption. Proper incident response follows the order of volatility, preserving memory contents before any system state changes.

    When this WOULD be correct

    In a scenario where the server is already compromised and the priority is to contain the threat to prevent lateral movement or further data encryption, shutting down the server may be the first action.

  • Create a forensic disk image of the hard drive

    Why it's wrong here

    Creating a forensic disk image is an important step for preserving persistent evidence, but it is not the immediate priority because the hard drive's contents will remain intact even after power is removed. Performing an image on a live system first wastes critical time while volatile memory—which holds running processes, open network connections, and in-memory malware—deteriorates with each passing second. The correct sequence is to acquire a memory dump first, then shut down and take a disk image from the powered-off system to avoid altering the original drive.

    When this WOULD be correct

    This would be correct if the server had already been powered off or if the question specified that memory acquisition was not possible (e.g., no tools available) and the priority was to preserve persistent data for offline analysis.

  • Run a full antivirus scan on the system

    Why it's wrong here

    Incorrect. Running an antivirus scan modifies the system state (e.g., by accessing files, creating logs, or quarantining malware) and can destroy volatile evidence. Scanning should be performed on a forensic copy, not the live system.

    When this WOULD be correct

    In a scenario where the server is already isolated and the goal is to identify and remove malware without immediate forensic preservation, running an antivirus scan could be the first step to stop active infection.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Capture a full memory dump of the serverCorrect answer

Why this is correct

Correct. Memory is the most volatile data and should be captured first to preserve evidence such as running processes, network connections, and malware in memory. Any delay or system shutdown may cause this data to be lost.

Shut down the server to prevent further damageWrong answer — click to see why

Why this is wrong here

Shutting down the server destroys volatile data in RAM, which is critical for ransomware analysis (e.g., encryption keys, running processes). The order of volatility dictates capturing memory first.

★ When this WOULD be the correct answer

In a scenario where the server is already compromised and the priority is to contain the threat to prevent lateral movement or further data encryption, shutting down the server may be the first action.

Why candidates choose this

Candidates often think stopping the ransomware's execution immediately will limit damage, but they overlook the forensic need to preserve volatile evidence before powering off.

Create a forensic disk image of the hard driveWrong answer — click to see why

Why this is wrong here

In a live ransomware incident, the order of volatility dictates that volatile data (memory) must be captured before non-volatile data (disk). Creating a disk image first risks losing critical evidence in memory, such as encryption keys or running processes.

★ When this WOULD be the correct answer

This would be correct if the server had already been powered off or if the question specified that memory acquisition was not possible (e.g., no tools available) and the priority was to preserve persistent data for offline analysis.

Why candidates choose this

Candidates often assume that preserving the hard drive is the most important step, not realizing that volatile memory contains crucial evidence that disappears when the system is shut down or altered.

Run a full antivirus scan on the systemWrong answer — click to see why

Why this is wrong here

Running a full antivirus scan modifies system files and memory, violating the order of volatility which prioritizes capturing volatile data (like memory) first to preserve evidence.

★ When this WOULD be the correct answer

In a scenario where the server is already isolated and the goal is to identify and remove malware without immediate forensic preservation, running an antivirus scan could be the first step to stop active infection.

Why candidates choose this

Candidates may think antivirus is a quick, safe action to stop ransomware, not realizing it alters evidence and contradicts forensic best practices.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.