Question 792 of 1,013
SY0-701 Security Operations Practice Question
A security analyst observes a critical server generating unusually high outbound traffic to an external IP address that is listed on a threat intelligence feed as a known command-and-control server. The analyst suspects the server is compromised. According to standard incident response procedures, what should the analyst do NEXT?
⚠ Common exam trap
It's easy for candidates to confuse the containment phase with eradication or recovery, choosing to reboot or patch immediately instead of isolating the system to stop the active threat and preserve evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the server from the network to stop the communication
Isolating the server from the network immediately stops the outbound command-and-control (C2) communication, preventing data exfiltration and further compromise. This aligns with the first step in the NIST SP 800-61 incident response process—containment—before any eradication or recovery actions are taken. Rebooting or patching without isolation could destroy volatile evidence (e.g., memory-resident malware) and allow the attacker to persist or escalate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reboot the server to clear any malicious processes from memory
Why it's wrong here
Rebooting a compromised server is counterproductive because it clears volatile memory, which often contains the malicious process code, active network socket states, and in-memory artifacts needed for forensic analysis. Most modern malware establishes persistence through registry keys, scheduled tasks, services, or startup folders, so a simple reboot will not eliminate the underlying infection; the attacker's beacon will simply reconnect and re-establish a foothold. Additionally, some advanced malware includes anti-forensic hooks that trigger on shutdown, actively deleting logs or credentials, thereby destroying evidence while failing to remediate the root cause.
When this WOULD be correct
This option would be correct in a scenario where the server is experiencing a non-persistent memory-only attack (e.g., a fileless malware) and the goal is to quickly restore operations while preserving the ability to analyze the attack from memory dumps taken before reboot.
- ✓
Isolate the server from the network to stop the communication
Why this is correct
Containment is the immediate priority in incident response. Isolating the server — by disabling the switch port, unplugging the network cable, or enforcing a host-based firewall rule — cuts off the established C2 channel, halts data exfiltration in progress, and prevents the attacker from pivoting laterally or issuing additional commands. This action preserves volatile evidence (memory, active connections, running processes) for forensic acquisition, unlike destructive measures such as rebooting, and aligns with the NIST SP 800-61 containment strategy, ensuring the threat is neutralized before any eradication or recovery steps are taken.
- ✗
Apply the latest security patches to the server
Why it's wrong here
Applying security patches is a remediation activity that belongs after the incident has been contained and the attacker eradicated; doing so first leaves the active C2 channel intact and allows the attacker to continue exfiltration during the patching window. On an already compromised host, the attacker may have tampered with the patching mechanism, installed a backdoor independent of the patched vulnerability, or granted themselves alternate access, so patching does nothing to remove their persistence. Furthermore, the patching process itself may alert the attacker to detection, prompting them to delete evidence or accelerate data theft before the server is properly isolated.
When this WOULD be correct
A question where a vulnerability scan reveals a critical unpatched flaw on a non-critical system, and the scenario asks for the best next step to reduce risk before an exploit occurs.
- ✗
Ignore the alert because the external IP might be a false positive
Why it's wrong here
Dismissing the alert as a false positive solely because the destination is an external IP is reckless, especially when the alert correlates with a known threat intelligence feed. While IDS/IPS false positives are common, a critical server communicating with a suspicious external endpoint matches the classic behavioral signature of C2 traffic, and the potential impact of an actual breach outweighs the cost of immediate investigation. Proper incident response assumes compromise until proven otherwise — you can later verify the IP's reputation and alert accuracy, but only after taking steps to stop the live communication, because ignoring the alert could lead to a successful data breach.
When this WOULD be correct
This option would be correct if the question stated that the traffic was to a commonly used benign service (e.g., a CDN) and the threat feed had a high false-positive rate, and the analyst had verified no other indicators of compromise.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Isolate the server from the network to stop the communicationCorrect answer▾
Why this is correct
Containment is the immediate priority in incident response. Isolating the server — by disabling the switch port, unplugging the network cable, or enforcing a host-based firewall rule — cuts off the established C2 channel, halts data exfiltration in progress, and prevents the attacker from pivoting laterally or issuing additional commands. This action preserves volatile evidence (memory, active connections, running processes) for forensic acquisition, unlike destructive measures such as rebooting, and aligns with the NIST SP 800-61 containment strategy, ensuring the threat is neutralized before any eradication or recovery steps are taken.
✗Reboot the server to clear any malicious processes from memoryWrong answer — click to see why▾
Why this is wrong here
Rebooting the server may temporarily disrupt malicious processes, but it does not stop the ongoing command-and-control communication and could destroy forensic evidence. The immediate priority is to contain the threat by isolating the server from the network.
★ When this WOULD be the correct answer
This option would be correct in a scenario where the server is experiencing a non-persistent memory-only attack (e.g., a fileless malware) and the goal is to quickly restore operations while preserving the ability to analyze the attack from memory dumps taken before reboot.
Why candidates choose this
Candidates may think rebooting is a quick fix to remove malware, but they overlook that it does not address active network communication and can hinder forensic investigation.
✗Apply the latest security patches to the serverWrong answer — click to see why▾
Why this is wrong here
Applying patches is a remediation step that should occur after containment; the immediate priority is to stop the active C2 communication by isolating the server.
★ When this WOULD be the correct answer
A question where a vulnerability scan reveals a critical unpatched flaw on a non-critical system, and the scenario asks for the best next step to reduce risk before an exploit occurs.
Why candidates choose this
Candidates often confuse remediation with containment, thinking patching will fix the issue, but it does not stop ongoing malicious traffic and may alert the attacker.
✗Ignore the alert because the external IP might be a false positiveWrong answer — click to see why▾
Why this is wrong here
Ignoring the alert based on a potential false positive is inappropriate because the traffic matches a known C2 indicator, and the high outbound volume suggests active compromise. Incident response requires immediate action to contain the threat.
★ When this WOULD be the correct answer
This option would be correct if the question stated that the traffic was to a commonly used benign service (e.g., a CDN) and the threat feed had a high false-positive rate, and the analyst had verified no other indicators of compromise.
Why candidates choose this
Candidates may think that threat intelligence feeds are not always accurate and that ignoring the alert avoids unnecessary disruption, but standard procedure requires verification, not dismissal.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.