Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A security analyst receives an alert from the intrusion detection system (IDS) indicating a high volume of outbound traffic from a single internal workstation to an external IP address known to be associated with a command-and-control (C2) server. The workstation's user reports no unusual activity. Which of the following should the analyst do FIRST?

⚠ Common exam trap

CompTIA often tests the principle that containment (disconnecting the network) must precede eradication (antivirus scan) or analysis (log review), and the trap here is that candidates choose a less disruptive step like running a scan or checking logs, thinking they need more data before acting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disconnect the workstation from the network.

The IDS alert indicates a high volume of outbound traffic to a known C2 server, which strongly suggests the workstation is compromised and communicating with an attacker. Disconnecting the workstation from the network (Option A) is the immediate containment step to prevent data exfiltration and further C2 communication, following the NIST incident response framework's containment phase. This action stops the threat at the network layer without waiting for additional analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disconnect the workstation from the network.

    Why this is correct

    Disconnecting the workstation from the network is the immediate containment action because it severs the active command-and-control channel, preventing data exfiltration and halting any further lateral movement. Unlike shutting down, this preserves volatile evidence such as running processes, open network connections, and memory-resident malware, which are critical for forensic analysis and determining the full scope of the compromise.

  • Run a full antivirus scan on the workstation.

    Why it's wrong here

    While scanning may be part of the investigation, it is not the first priority. The system is actively communicating with a C2 server, and delaying containment could allow data theft or additional compromise. Containment should come before remediation.

    When this WOULD be correct

    This would be the correct first step if the alert indicated a low-priority anomaly (e.g., a single outbound connection to a non-malicious IP) and the analyst needed to verify the workstation's security posture before escalating.

  • Review firewall logs to see if the traffic is being blocked.

    Why it's wrong here

    Reviewing firewall logs is a passive, investigative step that does not interrupt the ongoing communication with the C2 server. The analyst already knows the traffic is malicious from the intrusion alert, so the priority is to contain the live threat before collecting logs; delaying action allows the attacker to continue issuing commands and potentially encrypt or steal data. Log analysis should follow containment, not precede it.

    When this WOULD be correct

    This option would be correct if the question asked: 'After containing a potential C2 infection, which step should the analyst take to verify if the IDS alert was a false positive?' In that scenario, reviewing firewall logs helps confirm whether the traffic was actually blocked or allowed.

  • Inform the user to shut down the workstation.

    Why it's wrong here

    Telling the user to shut down the workstation would stop the network traffic, but it does so at the cost of destroying volatile forensic evidence, including running processes, open sockets, and memory artifacts, making root-cause analysis difficult. Additionally, instructing a non-technical user introduces delay and the risk of improper handling, whereas the analyst can perform a controlled network isolation that halts the C2 traffic while preserving the system state for later evidence collection.

    When this WOULD be correct

    This option would be correct if the question stated that the workstation is exhibiting signs of a severe malware infection (e.g., ransomware encrypting files) and the analyst's goal is to prevent further damage to the system itself, with network containment already in place or not the primary concern.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Disconnect the workstation from the network.Correct answer

Why this is correct

Disconnecting the workstation from the network is the immediate containment action because it severs the active command-and-control channel, preventing data exfiltration and halting any further lateral movement. Unlike shutting down, this preserves volatile evidence such as running processes, open network connections, and memory-resident malware, which are critical for forensic analysis and determining the full scope of the compromise.

Run a full antivirus scan on the workstation.Wrong answer — click to see why

Why this is wrong here

Running a full antivirus scan is a secondary step after containing the threat; the immediate priority is to stop potential data exfiltration or further C2 communication by disconnecting the workstation from the network.

★ When this WOULD be the correct answer

This would be the correct first step if the alert indicated a low-priority anomaly (e.g., a single outbound connection to a non-malicious IP) and the analyst needed to verify the workstation's security posture before escalating.

Why candidates choose this

Candidates often default to scanning as a standard response to malware alerts, overlooking that containment is critical when active C2 traffic is detected.

Review firewall logs to see if the traffic is being blocked.Wrong answer — click to see why

Why this is wrong here

Reviewing firewall logs to see if traffic is being blocked is a secondary step; the immediate priority is to contain the potential compromise by disconnecting the workstation from the network to prevent further C2 communication.

★ When this WOULD be the correct answer

This option would be correct if the question asked: 'After containing a potential C2 infection, which step should the analyst take to verify if the IDS alert was a false positive?' In that scenario, reviewing firewall logs helps confirm whether the traffic was actually blocked or allowed.

Why candidates choose this

Candidates may think that checking firewall logs is a quick way to validate the alert without disrupting the user, but they overlook the urgency of stopping active C2 traffic.

Inform the user to shut down the workstation.Wrong answer — click to see why

Why this is wrong here

In this scenario, the priority is to contain the potential compromise immediately by disconnecting the workstation from the network. Instructing the user to shut down the workstation could destroy volatile evidence (e.g., memory contents) and does not prevent the C2 traffic from continuing during the shutdown process.

★ When this WOULD be the correct answer

This option would be correct if the question stated that the workstation is exhibiting signs of a severe malware infection (e.g., ransomware encrypting files) and the analyst's goal is to prevent further damage to the system itself, with network containment already in place or not the primary concern.

Why candidates choose this

Candidates may think shutting down the workstation is a quick way to stop the traffic and prevent further damage, but they overlook the need to preserve evidence and the fact that disconnecting the network is a more effective containment step.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.