SY0-701 Security Operations Practice Question
A security analyst receives an automated alert indicating that a standard user account logged in from a geographic location that is unusual for the user, and the login occurred at 3:00 AM local time. The analyst has not yet verified whether this was a successful login or if any additional suspicious activity occurred. According to standard incident response procedures, what should the analyst do NEXT?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the account's recent activity for signs of compromise.
The correct next step is to review the account's recent activity to gather more context. According to the NIST incident response process (Preparation, Detection & Analysis, Containment, Eradication & Recovery, Post-Incident Activity), after detection the analyst should perform analysis to validate the alert and determine the scope. Reviewing recent logins, accessed files, and other actions helps decide if containment is needed. Immediately disabling the account (A) could be premature if the alert is a false positive or if the user is traveling. Conducting a full forensic analysis (B) is too resource-intensive for a single alert without further evidence. Reporting to law enforcement (D) is not appropriate at this stage; that would occur after a confirmed incident that meets legal thresholds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the user account immediately and reset the password.
Why it's wrong here
Disabling the account immediately may be too aggressive without confirming the login was malicious. It could disrupt legitimate user activity if the alert is a false positive (e.g., the user is traveling). Proper incident response requires analysis before containment.
When this WOULD be correct
This would be correct if the question stated that the account had been confirmed compromised (e.g., multiple failed logins followed by a successful login from an unusual location, and evidence of data exfiltration). In that scenario, immediate containment is necessary to prevent further damage.
- ✗
Conduct a full forensic analysis of the user's workstation.
Why it's wrong here
A full forensic analysis is not the immediate next step for a single anomalous login alert. Such an in-depth investigation is reserved for confirmed compromises or incidents with significant impact. It would be premature and resource-intensive at this point.
When this WOULD be correct
This option would be correct in a scenario where the analyst has already confirmed that the user's account was compromised and malicious activity has been detected on the workstation, such as unauthorized file access or malware execution. The question would state that the incident is confirmed and requires in-depth investigation.
- ✓
Review the account's recent activity for signs of compromise.
Why this is correct
Reviewing recent activity (e.g., successful logins, file access, privilege escalation attempts) is the appropriate analysis step to validate the alert. This helps determine if the account is compromised and guides subsequent containment and eradication actions.
- ✗
Report the incident to law enforcement.
Why it's wrong here
Law enforcement reporting is typically reserved for incidents that involve criminal activity, data breaches, or legal obligations. This single alert does not yet warrant such a report; the incident must first be investigated and confirmed.
When this WOULD be correct
This option would be correct if the question stated that the analyst has already confirmed a successful breach involving sensitive data exfiltration or a ransomware attack, and the organization's policy mandates immediate law enforcement notification as part of the incident response plan.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Review the account's recent activity for signs of compromise.Correct answer▾
Why this is correct
Reviewing recent activity (e.g., successful logins, file access, privilege escalation attempts) is the appropriate analysis step to validate the alert. This helps determine if the account is compromised and guides subsequent containment and eradication actions.
✗Disable the user account immediately and reset the password.Wrong answer — click to see why▾
Why this is wrong here
Disabling the account and resetting the password is premature because the analyst has not yet confirmed the login was successful or that any compromise occurred. Standard incident response procedures require initial triage and verification before taking containment actions.
★ When this WOULD be the correct answer
This would be correct if the question stated that the account had been confirmed compromised (e.g., multiple failed logins followed by a successful login from an unusual location, and evidence of data exfiltration). In that scenario, immediate containment is necessary to prevent further damage.
Why candidates choose this
Candidates may think that any suspicious login warrants immediate account disablement as a precaution, but they overlook the need to first verify the alert and gather context to avoid unnecessary disruption.
✗Conduct a full forensic analysis of the user's workstation.Wrong answer — click to see why▾
Why this is wrong here
Conducting a full forensic analysis of the user's workstation is premature at this stage because the alert only indicates an unusual login; the analyst has not yet verified if the login was successful or if any compromise occurred. Standard incident response procedures require initial triage and verification before escalating to forensic analysis.
★ When this WOULD be the correct answer
This option would be correct in a scenario where the analyst has already confirmed that the user's account was compromised and malicious activity has been detected on the workstation, such as unauthorized file access or malware execution. The question would state that the incident is confirmed and requires in-depth investigation.
Why candidates choose this
Candidates may think that any suspicious login warrants immediate deep investigation, confusing the urgency of the alert with the need for forensic analysis, rather than following a step-by-step incident response process.
✗Report the incident to law enforcement.Wrong answer — click to see why▾
Why this is wrong here
Reporting to law enforcement is premature at this stage because the analyst has not yet verified if the login was successful or if any malicious activity occurred. Standard incident response procedures require initial triage and confirmation of a security incident before involving external authorities.
★ When this WOULD be the correct answer
This option would be correct if the question stated that the analyst has already confirmed a successful breach involving sensitive data exfiltration or a ransomware attack, and the organization's policy mandates immediate law enforcement notification as part of the incident response plan.
Why candidates choose this
Candidates may think that any unusual login activity, especially from a foreign location, automatically constitutes a crime that must be reported to law enforcement, overlooking the need for verification and internal escalation first.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.