SY0-701 Security Operations Practice Question
A security analyst receives multiple alerts indicating that several users in the finance department clicked a malicious link in an email. The analyst has confirmed the email subject line and sender address. Which of the following is the BEST first step to contain the incident?
⚠ Common exam trap
Many candidates confuse containment with eradication or investigation, choosing to delete emails (Option D) or analyze them (Option C) first, when the immediate priority is to stop the attack vector at the gateway to prevent further compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block the sender's email address at the email gateway.
Blocking the sender's email address at the email gateway is the best first step because it immediately prevents further malicious emails from that sender from reaching any users, containing the incident at the perimeter. This action stops the spread of the attack without disrupting user productivity or requiring time-consuming analysis, aligning with the priority of containment in incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Block the sender's email address at the email gateway.
Why this is correct
Implementing a sender block at the email gateway (MTA) immediately suppresses messages from the malicious address before they reach the internal mail servers, unlike client-side rules. This leverages gateway filtering policies and can be combined with sender reputation scoring to proactively stop related spoofed or lookalike domains. This containment step halts the attack vector at the ingress point, preventing additional users from receiving the phishing payload while the investigation continues.
- ✗
Disable the users' accounts.
Why it's wrong here
Disabling user accounts is a disruptive and broad action that halts all authenticated access, including legitimate productivity, and it does not prevent the email gateway from accepting additional malicious messages. Since the attack propagates via email delivery, the correct target is the message transport path, not the recipients' authentication state. Account disabling is reserved for compromised accounts or insider threats, not as a primary response to an email-based phishing campaign.
When this WOULD be correct
This would be correct if the question stated that the malicious link led to credential harvesting and the users' accounts are actively compromised, requiring immediate account lockdown to prevent unauthorized access.
- ✗
Perform a forensic analysis of the emails.
Why it's wrong here
Performing forensic analysis first is premature because it consumes time during an active incident, allowing more users to interact with the malicious messages. While examining headers, attachments, and links is necessary to identify the attack's scope and IOCs, it should follow immediate containment to stop lateral spread. Forensic analysis is a reactive, post-containment step that supports eradication, not an initial response action.
- ✗
Delete the emails from the users' mailboxes.
Why it's wrong here
Deleting messages from mailboxes only remediates messages that have already bypassed the gateway and arrived in user inboxes; it does not stop the sender from delivering new emails or block the delivery mechanism itself. This action addresses the symptoms rather than the source, leaving the email channel open for subsequent waves of the attack. Content-based deletion may also miss unread messages in other folders or quarantine, so it is an incomplete containment measure compared to gateway-level sender blocking.
When this WOULD be correct
This would be correct if the question asked for the best step to prevent users from accessing the malicious link after the email has already been delivered, and blocking at the gateway is not an option (e.g., email gateway is down).
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Block the sender's email address at the email gateway.Correct answer▾
Why this is correct
Implementing a sender block at the email gateway (MTA) immediately suppresses messages from the malicious address before they reach the internal mail servers, unlike client-side rules. This leverages gateway filtering policies and can be combined with sender reputation scoring to proactively stop related spoofed or lookalike domains. This containment step halts the attack vector at the ingress point, preventing additional users from receiving the phishing payload while the investigation continues.
✗Disable the users' accounts.Wrong answer — click to see why▾
Why this is wrong here
Disabling users' accounts is a more disruptive step that should be taken after containing the email threat at the gateway. The immediate priority is to block the malicious email source to prevent further users from clicking the link, not to disable accounts of users who already clicked.
★ When this WOULD be the correct answer
This would be correct if the question stated that the malicious link led to credential harvesting and the users' accounts are actively compromised, requiring immediate account lockdown to prevent unauthorized access.
Why candidates choose this
Candidates may think that disabling accounts is the fastest way to stop further damage, but they overlook that the email gateway block is less disruptive and addresses the root cause (the email itself) rather than just the symptoms.
✗Delete the emails from the users' mailboxes.Wrong answer — click to see why▾
Why this is wrong here
Deleting emails from mailboxes does not prevent users from clicking similar future emails from the same sender, nor does it block the sender's ability to send more malicious emails. Containment requires blocking at the gateway to stop all emails from that sender.
★ When this WOULD be the correct answer
This would be correct if the question asked for the best step to prevent users from accessing the malicious link after the email has already been delivered, and blocking at the gateway is not an option (e.g., email gateway is down).
Why candidates choose this
Candidates may think removing the malicious email from the inbox directly eliminates the threat, overlooking that the sender can still send more emails and that blocking at the gateway is more effective for containment.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.