SY0-701 Security Operations Practice Question
A security analyst receives an alert that a user clicked a link in a phishing email and entered their corporate credentials on a fake login page. Which of the following should the analyst do FIRST to minimize further damage?
⚠ Common exam trap
A common mix-up: candidates choose to reset the password first (Option B) because it seems like a direct fix, but they fail to recognize that the compromised system itself may be under attacker control, and without network isolation, the attacker could still pivot or use other stolen credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the user's account and block the compromised system from the network
Immediately disabling the user's account and blocking the compromised system from the network stops the attacker from using the stolen credentials to authenticate to corporate resources, such as email, VPN, or file shares. This containment step is the highest priority in incident response to prevent lateral movement and further compromise, as the attacker already has valid credentials and could be actively using them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on the user's workstation
Why it's wrong here
Running an antivirus scan is not the first step because the incident is a credential theft via phishing, not a malware infection. While the system may have been compromised, containment of the credentials is more urgent.
When this WOULD be correct
This would be correct if the question stated that the user's credentials were already reset and the account was secured, and the next step is to ensure the workstation is free from malware that could exfiltrate data or provide persistent access.
- ✗
Reset the user's password and force re-authentication
Why it's wrong here
Resetting the user's password and forcing re-authentication fails as a first step because password resets do not revoke already-issued session tokens, cookies, or OAuth refresh tokens in many SSO and federated identity systems, allowing the attacker to remain authenticated. It also leaves the compromised endpoint connected to the network, so any keylogger or credential-stealing malware on that host can simply capture the new password when the user types it. Worse, an active attacker who notices the forced re-auth prompt knows their access was detected and may accelerate exfiltration or plant backdoors before you regain control. Containment — disabling the account and isolating the host — must precede any credential-reset action.
When this WOULD be correct
This would be correct if the question stated that the user's account was not yet compromised (e.g., the user reported the phishing email before entering credentials) and the goal is to proactively protect the account from potential misuse.
- ✓
Disable the user's account and block the compromised system from the network
Why this is correct
Disabling the user's account terminates the attacker's authenticated sessions and invalidates stolen credentials, while blocking the compromised system at the network layer severs any existing command-and-control, RDP, or file-transfer connections. This containment step is the immediate priority because it prevents lateral movement and data exfiltration without destroying volatile evidence on the host. In contrast to reactive scanning or password resets, isolating first gives the incident response team a clean boundary to perform forensic acquisition and threat hunting.
- ✗
Contact law enforcement and report the phishing site
Why it's wrong here
Contacting law enforcement and reporting the phishing site is an important post-containment step, but it does nothing to stop an attacker who currently holds valid credentials. Law enforcement processes are inherently slow and require chain-of-custody documentation that is only meaningful after the organization has secured its own environment. Furthermore, initiating external communication before containment can alert the adversary through publicly observable actions, giving them time to destroy logs or deploy persistence. The IR plan should first mitigate the verified threat, then escalate to authorities with a preserved evidence package.
When this WOULD be correct
This option would be correct if the question asked: 'After containing the incident and preserving evidence, which of the following should the analyst do to assist in the investigation and prosecution of the attacker?'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Disable the user's account and block the compromised system from the networkCorrect answer▾
Why this is correct
Disabling the user's account terminates the attacker's authenticated sessions and invalidates stolen credentials, while blocking the compromised system at the network layer severs any existing command-and-control, RDP, or file-transfer connections. This containment step is the immediate priority because it prevents lateral movement and data exfiltration without destroying volatile evidence on the host. In contrast to reactive scanning or password resets, isolating first gives the incident response team a clean boundary to perform forensic acquisition and threat hunting.
✗Run a full antivirus scan on the user's workstationWrong answer — click to see why▾
Why this is wrong here
Running a full antivirus scan is a reactive step that does not immediately prevent further unauthorized access or credential misuse. The priority is to contain the breach by disabling the account and isolating the system.
★ When this WOULD be the correct answer
This would be correct if the question stated that the user's credentials were already reset and the account was secured, and the next step is to ensure the workstation is free from malware that could exfiltrate data or provide persistent access.
Why candidates choose this
Candidates may think that malware is the primary threat from phishing and that scanning will remove any backdoors, overlooking the immediate need to stop credential abuse.
✗Reset the user's password and force re-authenticationWrong answer — click to see why▾
Why this is wrong here
Resetting the password and forcing re-authentication does not immediately isolate the compromised system or prevent the attacker from using the stolen credentials to access other resources before the password change takes effect.
★ When this WOULD be the correct answer
This would be correct if the question stated that the user's account was not yet compromised (e.g., the user reported the phishing email before entering credentials) and the goal is to proactively protect the account from potential misuse.
Why candidates choose this
Candidates often think that changing the password is the fastest way to revoke access, but they overlook the need to first disable the account and block the system to stop ongoing lateral movement or data exfiltration.
✗Contact law enforcement and report the phishing siteWrong answer — click to see why▾
Why this is wrong here
Contacting law enforcement is not the first priority; immediate containment actions like disabling the account and blocking the system are needed to prevent further credential misuse.
★ When this WOULD be the correct answer
This option would be correct if the question asked: 'After containing the incident and preserving evidence, which of the following should the analyst do to assist in the investigation and prosecution of the attacker?'
Why candidates choose this
Candidates may think reporting the phishing site to law enforcement is a critical early step, but they overlook the need for immediate containment to stop ongoing damage.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.