Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A security analyst receives an alert about a user account that has been attempting to authenticate from an unusual geographic location outside of business hours. The analyst reviews the event logs and sees that the authentication attempt was successful, but the user has not reported any suspicious activity. Which of the following actions should the analyst take NEXT?

⚠ Common exam trap

The trap here is that candidates often jump to containment (disabling the account) without first validating the alert, confusing the 'detection and analysis' phase with the 'containment, eradication, and recovery' phase of the incident response process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Contact the user to verify whether the authentication was legitimate

The correct next step is to contact the user to verify whether the authentication was legitimate. Since the authentication was successful and the user has not reported suspicious activity, the analyst must first gather context from the user before taking any disruptive action. This aligns with the incident response process of validation and scoping before containment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disable the user account immediately to prevent further access

    Why it's wrong here

    Disabling the account without first verifying with the user is too hasty. The activity could be legitimate (e.g., the user is on vacation) and disabling the account could cause unnecessary business disruption. Incident response best practices recommend gathering more information before taking irreversible actions.

    When this WOULD be correct

    If the question stated that the account was confirmed compromised (e.g., multiple failed attempts from unknown IPs, or the user reported suspicious activity), then disabling the account would be the correct next step to prevent further unauthorized access.

  • Contact the user to verify whether the authentication was legitimate

    Why this is correct

    Contacting the user is the appropriate next step in the incident response process. The analyst needs to confirm if the user performed the action. If the user denies it, the account is likely compromised, and the incident should be escalated. This step helps avoid false positives and ensures accurate incident handling.

  • Continuously monitor the account for additional suspicious activity

    Why it's wrong here

    While monitoring is a valid security operation, it should not be the next action when a successful authentication from an unusual location is detected. Waiting could allow an attacker to continue using the account, potentially accessing sensitive data. The analyst should actively investigate rather than passively monitor.

  • Revoke all active sessions for the user account

    Why it's wrong here

    Revoking all sessions without first confirming whether the activity is legitimate could lock the user out of necessary systems, causing productivity loss. It also does not address the root cause if the account is compromised, as the attacker might simply initiate new sessions. The proper approach is to verify with the user before taking containment actions.

    When this WOULD be correct

    In a scenario where a user account is confirmed compromised (e.g., the user reports suspicious activity or multiple failed logins precede a successful login), the analyst should revoke all active sessions to contain the breach before further investigation.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Contact the user to verify whether the authentication was legitimateCorrect answer

Why this is correct

Contacting the user is the appropriate next step in the incident response process. The analyst needs to confirm if the user performed the action. If the user denies it, the account is likely compromised, and the incident should be escalated. This step helps avoid false positives and ensures accurate incident handling.

Disable the user account immediately to prevent further accessWrong answer — click to see why

Why this is wrong here

Disabling the account immediately is premature without first verifying if the authentication was legitimate, as it could be the user themselves accessing from a remote location.

★ When this WOULD be the correct answer

If the question stated that the account was confirmed compromised (e.g., multiple failed attempts from unknown IPs, or the user reported suspicious activity), then disabling the account would be the correct next step to prevent further unauthorized access.

Why candidates choose this

Candidates may think any unusual authentication warrants immediate account disablement to stop potential threats, overlooking the need for verification first.

Revoke all active sessions for the user accountWrong answer — click to see why

Why this is wrong here

Revoking all active sessions is premature without first verifying if the authentication was legitimate; the user may have been traveling or using a VPN, and immediate revocation could disrupt legitimate work.

★ When this WOULD be the correct answer

In a scenario where a user account is confirmed compromised (e.g., the user reports suspicious activity or multiple failed logins precede a successful login), the analyst should revoke all active sessions to contain the breach before further investigation.

Why candidates choose this

Candidates may think that any unusual authentication warrants immediate session termination to prevent potential damage, overlooking the need for verification first.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A SIEM alert shows a payroll administrator account signed in at 02:10 from a country the employee has never visited. The employee says they are on vacation at home and did not travel. What should the analyst do first?

easy
  • A.Immediately disable the account and wait for the employee to return.
  • B.Verify the login context with the user or manager and review recent authentication history.
  • C.Close the alert as a false positive because the user is on vacation.
  • D.Reimage the user’s workstation before checking any logs.

Why B: The first step in incident response is to verify the alert's validity and gather context before taking action. The analyst should review the SIEM logs for authentication details (e.g., source IP, geolocation, timestamp) and confirm with the user or manager whether the login was expected. This aligns with the NIST SP 800-61 incident response process, which emphasizes triage and validation before containment.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.