Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A SOC analyst confirms that a workstation is encrypting local files and attempting SMB connections to nearby hosts. The user is still logged in, and the business wants to limit spread without destroying evidence. What is the best immediate action?

⚠ Common exam trap

Many exam-takers think powering off (Option A) is the fastest way to stop spread, but CompTIA emphasizes preserving evidence and avoiding destruction of volatile data, making network quarantine the correct choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Quarantine the workstation from the network using EDR or switch port containment

Quarantining the workstation via EDR or switch port containment immediately stops the SMB-based lateral movement and further encryption of network shares, while preserving the volatile evidence (memory, running processes, encryption keys) for forensic analysis. This aligns with the business requirement to limit spread without destroying evidence, as powering off or reimaging would lose critical forensic data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Power the workstation off immediately and leave it in place

    Why it's wrong here

    Powering the workstation off immediately is a volatile-evidence-destroying action. It terminates the RAM contents that often hold indicators of compromise (IOCs) such as running malicious processes, open network sockets, and unencrypted encryption keys, while also severing the ability to capture live memory forensics. It also performs no isolation: the attack may already have moved laterally to other systems, and the sudden power loss can trigger anti-forensic routines or corrupt logs on the disk. Therefore, it is a poor first response because it sacrifices forensic insight without providing controlled containment.

  • Quarantine the workstation from the network using EDR or switch port containment

    Why this is correct

    This is the best immediate containment action because it stops further spread while preserving evidence. EDR quarantine or disabling the switch port isolates the infected host without unnecessarily powering it down. The SOC can then collect volatile and disk evidence, determine the scope of infection, and proceed with eradication and recovery steps in the proper incident response sequence.

  • Run a full antivirus scan while the workstation remains connected

    Why it's wrong here

    Running a full antivirus scan with the workstation still on the network fails to stop the active encryption or prevent lateral movement, so it is not a containment measure. The scan relies on signature definitions that may not yet recognize the ransomware variant, and while the scan runs, the malware can continue mapping and encrypting network shares or communicating with its C2 server. Additionally, the heavy I/O and file-access activity from the scan can overwrite unallocated space and degrade forensic artifacts, hindering later incident analysis. The correct priority is to isolate the host first, then use scanning only after containment as part of eradication.

  • Wipe and reimage the workstation from a standard build image

    Why it's wrong here

    Reimaging is an eradication/recovery step, not an initial response, and it permanently destroys all on-disk evidence needed to understand the incident. Wiping the drive removes the ransomware binary, log files, registry keys, and any clues about the initial access vector, making root cause analysis impossible. It also does nothing to contain the threat: if the ransomware has already spread through SMB or other mechanisms, the reimage leaves the rest of the network vulnerable, and the attacker could simply re-enter through a still-open backdoor. Proper incident response requires preserving evidence and isolating the host before any reimage decision is made.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.