Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A security analyst receives an alert from the intrusion detection system indicating that a workstation in the finance department has established an outbound connection to a known malicious IP address using an encrypted protocol. The analyst verifies the alert and checks the user's activity logs, which show no legitimate business reason for the connection. According to the incident response process, what should the analyst do NEXT?

⚠ Common exam trap

The SY0-701 exam often tests the order of the incident response phases (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident) and the trap here is that candidates jump to eradication or forensic analysis without first containing the active threat, which violates the fundamental priority of stopping the bleeding before cleaning up.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate the workstation from the network to contain the threat.

According to the NIST SP 800-61 incident response process, containment is the immediate priority after verification to prevent further damage or data exfiltration. Since the workstation has an active encrypted outbound connection to a known malicious IP with no legitimate business reason, isolating the network interface (e.g., disabling the port, blocking the MAC address, or unplugging the cable) stops the threat from communicating while preserving the system state for later analysis. This aligns with the containment phase, which must precede eradication or full forensic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Begin the eradication phase by immediately reimaging the workstation.

    Why it's wrong here

    Reimaging the workstation is an eradication and recovery activity that must not be performed before containment because it destroys all local evidence, including the initial infection vector and any attacker-created artifacts. It also fails to address other systems on the network that may already be compromised, allowing the threat to persist and spread while you rebuild this one host. Moreover, aggressive recovery steps should be deferred until law enforcement or incident responders have had the opportunity to collect forensic data, so early reimaging is both technically and procedurally inappropriate.

    When this WOULD be correct

    This option would be correct if the question stated that containment has already been performed (e.g., the workstation is already isolated) and the analyst has confirmed the system is compromised with no need for forensic preservation, so the next step is eradication.

  • Isolate the workstation from the network to contain the threat.

    Why this is correct

    Isolation is the immediate containment step in the NIST incident response lifecycle, and it should be performed as soon as a compromise is confirmed. By moving the workstation to a quarantine VLAN, disabling its network interface, or physically disconnecting it, you sever the active command-and-control channel and prevent the attacker from using this host to pivot laterally. This action also preserves volatile evidence in memory for later forensic acquisition, making it the correct first response to an intrusion alert.

  • Conduct a full forensic analysis of the workstation's hard drive.

    Why it's wrong here

    A full forensic analysis of the hard drive is an evidence-collection and investigation step that should occur only after the workstation has been isolated from the network. Before containment, the attacker can continue exfiltrating data or issuing commands while you spend hours imaging the disk, and a dead-box analysis of storage alone will miss volatile memory and active network connections. Proper forensic procedure follows the order of volatility, which means capturing memory and network state first, but those steps also assume the host is already under your control rather than still communicating with an adversary.

    When this WOULD be correct

    A question where the incident has already been contained, and the analyst is now in the eradication or post-incident activity phase, such as: 'After isolating the compromised workstation and blocking the malicious IP, what should the analyst do NEXT to gather evidence for legal proceedings?'

  • Update the firewall rule to block all outbound traffic to the malicious IP.

    Why it's wrong here

    While updating a firewall rule can help block further connections to the malicious IP, it does not address the already compromised workstation, which may still be able to use other protocols or paths to communicate out. Isolating the workstation is more immediate and comprehensive.

    When this WOULD be correct

    This would be correct if the question stated that the analyst had already contained the threat and was now implementing permanent controls to prevent recurrence, or if the scenario involved a known malicious IP that needed to be blocked proactively across the network.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Isolate the workstation from the network to contain the threat.Correct answer

Why this is correct

Isolation is the immediate containment step in the NIST incident response lifecycle, and it should be performed as soon as a compromise is confirmed. By moving the workstation to a quarantine VLAN, disabling its network interface, or physically disconnecting it, you sever the active command-and-control channel and prevent the attacker from using this host to pivot laterally. This action also preserves volatile evidence in memory for later forensic acquisition, making it the correct first response to an intrusion alert.

Begin the eradication phase by immediately reimaging the workstation.Wrong answer — click to see why

Why this is wrong here

In the incident response process, containment (isolating the workstation) must precede eradication (reimaging). Reimaging without containment could allow the threat to spread or lose volatile evidence.

★ When this WOULD be the correct answer

This option would be correct if the question stated that containment has already been performed (e.g., the workstation is already isolated) and the analyst has confirmed the system is compromised with no need for forensic preservation, so the next step is eradication.

Why candidates choose this

Candidates may think reimaging is a quick fix to remove malware, but they overlook the critical containment step required to prevent lateral movement and preserve evidence.

Conduct a full forensic analysis of the workstation's hard drive.Wrong answer — click to see why

Why this is wrong here

In the incident response process, containment (isolating the workstation) must occur before eradication or forensic analysis. Conducting a full forensic analysis at this stage would delay containment and allow the threat to persist or spread.

★ When this WOULD be the correct answer

A question where the incident has already been contained, and the analyst is now in the eradication or post-incident activity phase, such as: 'After isolating the compromised workstation and blocking the malicious IP, what should the analyst do NEXT to gather evidence for legal proceedings?'

Why candidates choose this

Candidates may think forensic analysis is the immediate next step to understand the attack, but they overlook the priority of containment to prevent further damage.

Update the firewall rule to block all outbound traffic to the malicious IP.Wrong answer — click to see why

Why this is wrong here

After confirming an active threat, the immediate priority is containment (isolating the workstation) to prevent further damage, not updating firewall rules, which is a longer-term preventive measure.

★ When this WOULD be the correct answer

This would be correct if the question stated that the analyst had already contained the threat and was now implementing permanent controls to prevent recurrence, or if the scenario involved a known malicious IP that needed to be blocked proactively across the network.

Why candidates choose this

Candidates may think blocking the IP is a quick fix to stop the connection, but they overlook that the workstation is already compromised and needs isolation first.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.