SY0-701 Security Operations Practice Question
A security analyst receives an alert about a user account that has been attempting to authenticate from an unusual geographic location outside of business hours. The analyst reviews the event logs and sees that the authentication attempt was successful, but the user has not reported any suspicious activity. Which of the following actions should the analyst take NEXT?
⚠ Common exam trap
The trap here is that candidates often jump to containment (disabling the account) without first validating the alert, confusing the 'detection and analysis' phase with the 'containment, eradication, and recovery' phase of the incident response process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Contact the user to verify whether the authentication was legitimate
The correct next step is to contact the user to verify whether the authentication was legitimate. Since the authentication was successful and the user has not reported suspicious activity, the analyst must first gather context from the user before taking any disruptive action. This aligns with the incident response process of validation and scoping before containment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the user account immediately to prevent further access
Why it's wrong here
Disabling the account without first verifying with the user is too hasty. The activity could be legitimate (e.g., the user is on vacation) and disabling the account could cause unnecessary business disruption. Incident response best practices recommend gathering more information before taking irreversible actions.
When this WOULD be correct
If the question stated that the account was confirmed compromised (e.g., multiple failed attempts from unknown IPs, or the user reported suspicious activity), then disabling the account would be the correct next step to prevent further unauthorized access.
- ✓
Contact the user to verify whether the authentication was legitimate
Why this is correct
Contacting the user is the appropriate next step in the incident response process. The analyst needs to confirm if the user performed the action. If the user denies it, the account is likely compromised, and the incident should be escalated. This step helps avoid false positives and ensures accurate incident handling.
- ✗
Continuously monitor the account for additional suspicious activity
Why it's wrong here
While monitoring is a valid security operation, it should not be the next action when a successful authentication from an unusual location is detected. Waiting could allow an attacker to continue using the account, potentially accessing sensitive data. The analyst should actively investigate rather than passively monitor.
- ✗
Revoke all active sessions for the user account
Why it's wrong here
Revoking all sessions without first confirming whether the activity is legitimate could lock the user out of necessary systems, causing productivity loss. It also does not address the root cause if the account is compromised, as the attacker might simply initiate new sessions. The proper approach is to verify with the user before taking containment actions.
When this WOULD be correct
In a scenario where a user account is confirmed compromised (e.g., the user reports suspicious activity or multiple failed logins precede a successful login), the analyst should revoke all active sessions to contain the breach before further investigation.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Contact the user to verify whether the authentication was legitimateCorrect answer▾
Why this is correct
Contacting the user is the appropriate next step in the incident response process. The analyst needs to confirm if the user performed the action. If the user denies it, the account is likely compromised, and the incident should be escalated. This step helps avoid false positives and ensures accurate incident handling.
✗Disable the user account immediately to prevent further accessWrong answer — click to see why▾
Why this is wrong here
Disabling the account immediately is premature without first verifying if the authentication was legitimate, as it could be the user themselves accessing from a remote location.
★ When this WOULD be the correct answer
If the question stated that the account was confirmed compromised (e.g., multiple failed attempts from unknown IPs, or the user reported suspicious activity), then disabling the account would be the correct next step to prevent further unauthorized access.
Why candidates choose this
Candidates may think any unusual authentication warrants immediate account disablement to stop potential threats, overlooking the need for verification first.
✗Revoke all active sessions for the user accountWrong answer — click to see why▾
Why this is wrong here
Revoking all active sessions is premature without first verifying if the authentication was legitimate; the user may have been traveling or using a VPN, and immediate revocation could disrupt legitimate work.
★ When this WOULD be the correct answer
In a scenario where a user account is confirmed compromised (e.g., the user reports suspicious activity or multiple failed logins precede a successful login), the analyst should revoke all active sessions to contain the breach before further investigation.
Why candidates choose this
Candidates may think that any unusual authentication warrants immediate session termination to prevent potential damage, overlooking the need for verification first.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A SIEM alert shows a payroll administrator account signed in at 02:10 from a country the employee has never visited. The employee says they are on vacation at home and did not travel. What should the analyst do first?
easy- A.Immediately disable the account and wait for the employee to return.
- ✓ B.Verify the login context with the user or manager and review recent authentication history.
- C.Close the alert as a false positive because the user is on vacation.
- D.Reimage the user’s workstation before checking any logs.
Why B: The first step in incident response is to verify the alert's validity and gather context before taking action. The analyst should review the SIEM logs for authentication details (e.g., source IP, geolocation, timestamp) and confirm with the user or manager whether the login was expected. This aligns with the NIST SP 800-61 incident response process, which emphasizes triage and validation before containment.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.