SY0-701 Security Operations Practice Question
A SOC analyst detects that a user's workstation is sending large volumes of data to an unusual external IP address during non-business hours. The analyst has already isolated the workstation by disconnecting it from the network. What is the NEXT step in the incident response process?
⚠ Common exam trap
Test-takers frequently confuse containment with eradication, selecting reimaging (Option A) prematurely without recognizing that evidence preservation is a mandatory step before any destructive remediation in the incident response process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a forensic analysis of the workstation to collect evidence
After isolating the workstation, the next step in the incident response process is to perform forensic analysis to collect evidence. This aligns with the NIST SP 800-61 framework, where containment (isolation) is followed by eradication and recovery, but evidence collection must occur before any destructive actions like reimaging. The forensic analysis preserves volatile data (e.g., memory, network connections) and non-volatile data (e.g., disk artifacts) to determine the scope and cause of the data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reimage the workstation to remove any malware
Why it's wrong here
Reimaging the workstation is an eradication/recovery action that would completely destroy the digital evidence needed to determine how the exfiltration occurred and what data was taken. Forensic analysis must be performed first to create a bit-for-bit image of the disk and capture volatile data before any remediation step like reimaging is taken. Reimaging may be appropriate after evidence collection to restore the system to a known good state, but doing it immediately would compromise the entire investigation and potentially violate legal hold obligations.
When this WOULD be correct
This would be correct if the question stated that the workstation has already been forensically imaged and analyzed, and the next step is to remediate the infection and restore the system to a known good state.
- ✓
Perform a forensic analysis of the workstation to collect evidence
Why this is correct
After containment, performing forensic analysis on the workstation is the correct next step because it preserves volatile data (memory, network connections, running processes) and non-volatile evidence (logs, files, registry) in a forensically sound manner. This process establishes a chain of custody and enables investigators to identify the malware, infection vector, and scope of the exfiltration, which is essential for informed remediation and potential legal action.
- ✗
Reset the user's password to prevent further unauthorized access
Why it's wrong here
Resetting the user's password addresses only future unauthorized access and does nothing to investigate the ongoing or past data exfiltration, nor does it identify the root cause or the attacker's foothold. In fact, resetting the password could alter the system state, potentially destroying evidence such as active sessions, cached credentials, or persistence mechanisms that rely on the current authentication context. The correct approach is to preserve evidence through forensic collection before making any changes to the user account or system configuration.
When this WOULD be correct
This would be correct if the question described an active account compromise (e.g., phishing credentials stolen) and the workstation was not yet isolated, requiring immediate password reset to prevent further unauthorized access while other containment measures are taken.
- ✗
Notify law enforcement immediately
Why it's wrong here
Law enforcement notification is not the immediate next step because internal incident response must first assess the situation, preserve evidence, and follow organizational policy and legal counsel. Prematurely notifying law enforcement without a clear understanding of the incident could lead to loss of evidence, inaccurate reporting, or legal complications, especially since data exfiltration may involve jurisdictional and privacy considerations. While law enforcement may be contacted later for criminal prosecution, the immediate priority is forensic preservation and internal investigation.
When this WOULD be correct
This would be correct if the question stated that the incident involves confirmed illegal activity (e.g., child exploitation, terrorism) and the organization's policy mandates immediate law enforcement notification, or if the question asked for the first step after confirming a crime in progress.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Perform a forensic analysis of the workstation to collect evidenceCorrect answer▾
Why this is correct
After containment, performing forensic analysis on the workstation is the correct next step because it preserves volatile data (memory, network connections, running processes) and non-volatile evidence (logs, files, registry) in a forensically sound manner. This process establishes a chain of custody and enables investigators to identify the malware, infection vector, and scope of the exfiltration, which is essential for informed remediation and potential legal action.
✗Reimage the workstation to remove any malwareWrong answer — click to see why▾
Why this is wrong here
Reimaging the workstation destroys potential evidence before forensic analysis can be performed, violating the preservation step of incident response.
★ When this WOULD be the correct answer
This would be correct if the question stated that the workstation has already been forensically imaged and analyzed, and the next step is to remediate the infection and restore the system to a known good state.
Why candidates choose this
Candidates may think that removing malware is the immediate priority after isolation, not realizing that evidence collection must come first to support investigation and legal action.
✗Reset the user's password to prevent further unauthorized accessWrong answer — click to see why▾
Why this is wrong here
Resetting the user's password is a containment step, but the workstation is already isolated. The next step in the incident response process after containment is eradication or recovery, but more importantly, forensic analysis must be performed before any changes to preserve evidence.
★ When this WOULD be the correct answer
This would be correct if the question described an active account compromise (e.g., phishing credentials stolen) and the workstation was not yet isolated, requiring immediate password reset to prevent further unauthorized access while other containment measures are taken.
Why candidates choose this
Candidates may think that resetting the password is a quick way to stop the data exfiltration, especially if they confuse the user's credentials with the cause of the incident, or they skip the forensic step in favor of immediate remediation.
✗Notify law enforcement immediatelyWrong answer — click to see why▾
Why this is wrong here
Notifying law enforcement is premature at this stage; the incident response process requires evidence collection and internal investigation first to confirm the incident and gather necessary information before involving external authorities.
★ When this WOULD be the correct answer
This would be correct if the question stated that the incident involves confirmed illegal activity (e.g., child exploitation, terrorism) and the organization's policy mandates immediate law enforcement notification, or if the question asked for the first step after confirming a crime in progress.
Why candidates choose this
Candidates may believe that any suspicious data exfiltration requires immediate law enforcement involvement, especially if they think the incident is a serious breach, without understanding the standard incident response order of operations.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.