Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A SOC analyst detects that a user's workstation is sending large volumes of data to an unusual external IP address during non-business hours. The analyst has already isolated the workstation by disconnecting it from the network. What is the NEXT step in the incident response process?

⚠ Common exam trap

Test-takers frequently confuse containment with eradication, selecting reimaging (Option A) prematurely without recognizing that evidence preservation is a mandatory step before any destructive remediation in the incident response process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perform a forensic analysis of the workstation to collect evidence

After isolating the workstation, the next step in the incident response process is to perform forensic analysis to collect evidence. This aligns with the NIST SP 800-61 framework, where containment (isolation) is followed by eradication and recovery, but evidence collection must occur before any destructive actions like reimaging. The forensic analysis preserves volatile data (e.g., memory, network connections) and non-volatile data (e.g., disk artifacts) to determine the scope and cause of the data exfiltration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Reimage the workstation to remove any malware

    Why it's wrong here

    Reimaging the workstation is an eradication/recovery action that would completely destroy the digital evidence needed to determine how the exfiltration occurred and what data was taken. Forensic analysis must be performed first to create a bit-for-bit image of the disk and capture volatile data before any remediation step like reimaging is taken. Reimaging may be appropriate after evidence collection to restore the system to a known good state, but doing it immediately would compromise the entire investigation and potentially violate legal hold obligations.

    When this WOULD be correct

    This would be correct if the question stated that the workstation has already been forensically imaged and analyzed, and the next step is to remediate the infection and restore the system to a known good state.

  • Perform a forensic analysis of the workstation to collect evidence

    Why this is correct

    After containment, performing forensic analysis on the workstation is the correct next step because it preserves volatile data (memory, network connections, running processes) and non-volatile evidence (logs, files, registry) in a forensically sound manner. This process establishes a chain of custody and enables investigators to identify the malware, infection vector, and scope of the exfiltration, which is essential for informed remediation and potential legal action.

  • Reset the user's password to prevent further unauthorized access

    Why it's wrong here

    Resetting the user's password addresses only future unauthorized access and does nothing to investigate the ongoing or past data exfiltration, nor does it identify the root cause or the attacker's foothold. In fact, resetting the password could alter the system state, potentially destroying evidence such as active sessions, cached credentials, or persistence mechanisms that rely on the current authentication context. The correct approach is to preserve evidence through forensic collection before making any changes to the user account or system configuration.

    When this WOULD be correct

    This would be correct if the question described an active account compromise (e.g., phishing credentials stolen) and the workstation was not yet isolated, requiring immediate password reset to prevent further unauthorized access while other containment measures are taken.

  • Notify law enforcement immediately

    Why it's wrong here

    Law enforcement notification is not the immediate next step because internal incident response must first assess the situation, preserve evidence, and follow organizational policy and legal counsel. Prematurely notifying law enforcement without a clear understanding of the incident could lead to loss of evidence, inaccurate reporting, or legal complications, especially since data exfiltration may involve jurisdictional and privacy considerations. While law enforcement may be contacted later for criminal prosecution, the immediate priority is forensic preservation and internal investigation.

    When this WOULD be correct

    This would be correct if the question stated that the incident involves confirmed illegal activity (e.g., child exploitation, terrorism) and the organization's policy mandates immediate law enforcement notification, or if the question asked for the first step after confirming a crime in progress.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Perform a forensic analysis of the workstation to collect evidenceCorrect answer

Why this is correct

After containment, performing forensic analysis on the workstation is the correct next step because it preserves volatile data (memory, network connections, running processes) and non-volatile evidence (logs, files, registry) in a forensically sound manner. This process establishes a chain of custody and enables investigators to identify the malware, infection vector, and scope of the exfiltration, which is essential for informed remediation and potential legal action.

Reimage the workstation to remove any malwareWrong answer — click to see why

Why this is wrong here

Reimaging the workstation destroys potential evidence before forensic analysis can be performed, violating the preservation step of incident response.

★ When this WOULD be the correct answer

This would be correct if the question stated that the workstation has already been forensically imaged and analyzed, and the next step is to remediate the infection and restore the system to a known good state.

Why candidates choose this

Candidates may think that removing malware is the immediate priority after isolation, not realizing that evidence collection must come first to support investigation and legal action.

Reset the user's password to prevent further unauthorized accessWrong answer — click to see why

Why this is wrong here

Resetting the user's password is a containment step, but the workstation is already isolated. The next step in the incident response process after containment is eradication or recovery, but more importantly, forensic analysis must be performed before any changes to preserve evidence.

★ When this WOULD be the correct answer

This would be correct if the question described an active account compromise (e.g., phishing credentials stolen) and the workstation was not yet isolated, requiring immediate password reset to prevent further unauthorized access while other containment measures are taken.

Why candidates choose this

Candidates may think that resetting the password is a quick way to stop the data exfiltration, especially if they confuse the user's credentials with the cause of the incident, or they skip the forensic step in favor of immediate remediation.

Notify law enforcement immediatelyWrong answer — click to see why

Why this is wrong here

Notifying law enforcement is premature at this stage; the incident response process requires evidence collection and internal investigation first to confirm the incident and gather necessary information before involving external authorities.

★ When this WOULD be the correct answer

This would be correct if the question stated that the incident involves confirmed illegal activity (e.g., child exploitation, terrorism) and the organization's policy mandates immediate law enforcement notification, or if the question asked for the first step after confirming a crime in progress.

Why candidates choose this

Candidates may believe that any suspicious data exfiltration requires immediate law enforcement involvement, especially if they think the incident is a serious breach, without understanding the standard incident response order of operations.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.