Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A security analyst notices unusual outbound traffic from a server that normally only communicates with internal clients. The traffic is encrypted and goes to an external IP address not on any blocklists. The analyst also finds a new scheduled task on the server that runs a PowerShell script. Which of the following best describes the analyst's immediate next step in the incident response process?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disconnect the server from the network to contain the potential breach.

According to standard incident response frameworks such as NIST SP 800-61, containment is one of the first and most critical steps after detecting a potential compromise. The unusual encrypted outbound traffic and the unauthorized scheduled task are strong indicators of compromise (IOCs). Disconnecting the server from the network immediately helps prevent further data exfiltration, lateral movement, or additional damage. Other actions, such as running a scan, wiping the server, or notifying legal, are performed later in the process after containment and evidence preservation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disconnect the server from the network to contain the potential breach.

    Why this is correct

    This is correct because containment is the immediate priority in incident response to stop the threat from spreading or causing more harm. Disconnecting the network cable or disabling the network interface is a simple and effective containment action.

  • Wipe the server and restore from a known good backup.

    Why it's wrong here

    Wiping the server and restoring from a known good backup is premature and destructive during the initial response. This action destroys volatile evidence—memory contents, active network connections, running processes, and malicious artifacts on disk—that forensic analysts need to determine the attack vector, scope, and attacker behavior. Incident response best practice follows a sequence: contain, preserve evidence, analyze, then remediate and restore only after root cause is established. Additionally, restoration may be ineffective if the backup is compromised or the underlying vulnerability remains unpatched.

    When this WOULD be correct

    This would be correct if the question asked for the final step after containment and eradication, or if the server is confirmed to be compromised beyond repair and a clean restoration is the approved recovery method.

  • Run a full antivirus scan on the server to identify malware.

    Why it's wrong here

    While running an antivirus scan may be useful later, it is not the immediate next step. The scan could alert an attacker if the malware is configured to hide or delete evidence. Containment takes precedence to minimize potential damage.

    When this WOULD be correct

    This option would be correct if the question asked for the next step after containment, or if the scenario described no active threat and the goal was to identify the cause of a non-critical anomaly (e.g., a false positive alert).

  • Inform the legal department and law enforcement.

    Why it's wrong here

    Legal and law enforcement notification occurs after the incident has been confirmed, classified, and initial containment has been performed. Jumping to notification without first containing the threat could lead to further compromise and loss of evidence.

    When this WOULD be correct

    This would be correct as an immediate next step if the question stated that the incident has already been contained, evidence has been preserved, and the organization's policy requires mandatory reporting to legal and law enforcement before any further analysis or remediation.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Disconnect the server from the network to contain the potential breach.Correct answer

Why this is correct

This is correct because containment is the immediate priority in incident response to stop the threat from spreading or causing more harm. Disconnecting the network cable or disabling the network interface is a simple and effective containment action.

Wipe the server and restore from a known good backup.Wrong answer — click to see why

Why this is wrong here

Wiping and restoring from backup is a recovery step, not an immediate containment step. The incident response process requires containment first to prevent further damage or data exfiltration.

★ When this WOULD be the correct answer

This would be correct if the question asked for the final step after containment and eradication, or if the server is confirmed to be compromised beyond repair and a clean restoration is the approved recovery method.

Why candidates choose this

Candidates may confuse recovery actions with immediate response steps, or believe that restoring from backup is the fastest way to eliminate the threat without considering the need to preserve evidence and contain the incident first.

Run a full antivirus scan on the server to identify malware.Wrong answer — click to see why

Why this is wrong here

Running a full antivirus scan is a detection step, but the immediate priority in incident response is containment. The unusual outbound encrypted traffic and scheduled task indicate a potential compromise that must be isolated first to prevent data exfiltration or lateral movement.

★ When this WOULD be the correct answer

This option would be correct if the question asked for the next step after containment, or if the scenario described no active threat and the goal was to identify the cause of a non-critical anomaly (e.g., a false positive alert).

Why candidates choose this

Candidates often default to scanning for malware as a first response, especially when the symptom suggests malicious code, without recognizing that containment takes precedence to stop ongoing damage.

Inform the legal department and law enforcement.Wrong answer — click to see why

Why this is wrong here

Informing legal and law enforcement is not the immediate next step during incident response; containment (disconnecting the network) takes priority to prevent further damage or data exfiltration.

★ When this WOULD be the correct answer

This would be correct as an immediate next step if the question stated that the incident has already been contained, evidence has been preserved, and the organization's policy requires mandatory reporting to legal and law enforcement before any further analysis or remediation.

Why candidates choose this

Candidates may think that involving legal and law enforcement early is necessary due to legal obligations or fear of liability, but they overlook the immediate need to contain the threat first.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.