SY0-701 Security Operations Practice Question
A SOC analyst is reviewing logs from a Windows domain controller and notices a large number of failed logon attempts (Event ID 4625) from a single source IP address within a five-minute window. The account names used are random strings such as "a1b2c3", "x9y8z7", etc. The analyst then checks the source IP and finds it is a known external address from a foreign country. Which of the following is the most appropriate next step for the analyst to take?
⚠ Common exam trap
The trap here is that candidates may jump to immediate blocking (Option A) as a reflexive security action, but the SY0-701 emphasizes following the incident response process—identify and analyze before containing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate whether any of the attempted accounts correspond to actual domain users.
The analyst must first determine if any of the randomly generated account names match existing domain user accounts. If a match is found, it indicates a targeted password-spraying or brute-force attack against valid accounts, requiring immediate account lockdown and credential reset. This investigation step aligns with the incident response process of identification before containment or escalation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately block the IP address at the perimeter firewall.
Why it's wrong here
While blocking the malicious IP is a valid containment step, it should not be the first action. The analyst should first determine if any valid accounts were targeted, as a successful logon could have already occurred. Blocking prematurely might also hinder further observation of the attack pattern.
When this WOULD be correct
In a scenario where the SOC analyst has confirmed that the source IP is a known malicious C2 server actively exploiting a critical vulnerability (e.g., EternalBlue) and causing system compromise, immediate blocking at the firewall is the correct containment step.
- ✓
Investigate whether any of the attempted accounts correspond to actual domain users.
Why this is correct
This is the correct first step. If any of the random account names match legitimate domain accounts, it indicates a targeted attack and possible credential compromise. Even if no failures are logged, a successful authentication might have been recorded separately. This investigation guides subsequent containment and remediation.
- ✗
Run a full antivirus scan on the domain controller.
Why it's wrong here
An antivirus scan is not warranted at this point. The logs indicate an authentication attack, not malware activity. Scanning the domain controller would divert resources from addressing the immediate threat and would not prevent the ongoing logon attempts.
- ✗
Notify the company's legal department for law enforcement involvement.
Why it's wrong here
Legal involvement and reporting to law enforcement may be appropriate later, but it is premature before confirming that the attack is successful or that sensitive data has been accessed. The analyst should first investigate and contain the threat.
When this WOULD be correct
This would be correct if the question stated that the brute force attack successfully compromised a privileged account and sensitive data was exfiltrated, requiring legal notification for regulatory compliance or criminal investigation.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Investigate whether any of the attempted accounts correspond to actual domain users.Correct answer▾
Why this is correct
This is the correct first step. If any of the random account names match legitimate domain accounts, it indicates a targeted attack and possible credential compromise. Even if no failures are logged, a successful authentication might have been recorded separately. This investigation guides subsequent containment and remediation.
✗Immediately block the IP address at the perimeter firewall.Wrong answer — click to see why▾
Why this is wrong here
Blocking the IP immediately is premature without confirming the threat; the failed logins use random account names, suggesting a password spray or reconnaissance, but legitimate users might be affected if the IP is shared or spoofed.
★ When this WOULD be the correct answer
In a scenario where the SOC analyst has confirmed that the source IP is a known malicious C2 server actively exploiting a critical vulnerability (e.g., EternalBlue) and causing system compromise, immediate blocking at the firewall is the correct containment step.
Why candidates choose this
Candidates often default to blocking as a quick fix, but fail to consider that the incident response process requires investigation first to avoid disrupting legitimate traffic and to gather evidence.
✗Notify the company's legal department for law enforcement involvement.Wrong answer — click to see why▾
Why this is wrong here
Notifying legal/law enforcement is premature at this stage; the analyst first needs to determine if the failed logons pose an actual threat (e.g., successful brute force or valid account compromise) before escalating.
★ When this WOULD be the correct answer
This would be correct if the question stated that the brute force attack successfully compromised a privileged account and sensitive data was exfiltrated, requiring legal notification for regulatory compliance or criminal investigation.
Why candidates choose this
Candidates may think that any external attack from a foreign IP warrants immediate legal involvement, overlooking the need for initial investigation and incident triage.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
IP address
An IP address is a unique numerical label assigned to each device connected to a computer network that uses the Internet Protocol for communication.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.