Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A SOC analyst is reviewing logs from a Windows domain controller and notices a large number of failed logon attempts (Event ID 4625) from a single source IP address within a five-minute window. The account names used are random strings such as "a1b2c3", "x9y8z7", etc. The analyst then checks the source IP and finds it is a known external address from a foreign country. Which of the following is the most appropriate next step for the analyst to take?

⚠ Common exam trap

The trap here is that candidates may jump to immediate blocking (Option A) as a reflexive security action, but the SY0-701 emphasizes following the incident response process—identify and analyze before containing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Investigate whether any of the attempted accounts correspond to actual domain users.

The analyst must first determine if any of the randomly generated account names match existing domain user accounts. If a match is found, it indicates a targeted password-spraying or brute-force attack against valid accounts, requiring immediate account lockdown and credential reset. This investigation step aligns with the incident response process of identification before containment or escalation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Immediately block the IP address at the perimeter firewall.

    Why it's wrong here

    While blocking the malicious IP is a valid containment step, it should not be the first action. The analyst should first determine if any valid accounts were targeted, as a successful logon could have already occurred. Blocking prematurely might also hinder further observation of the attack pattern.

    When this WOULD be correct

    In a scenario where the SOC analyst has confirmed that the source IP is a known malicious C2 server actively exploiting a critical vulnerability (e.g., EternalBlue) and causing system compromise, immediate blocking at the firewall is the correct containment step.

  • Investigate whether any of the attempted accounts correspond to actual domain users.

    Why this is correct

    This is the correct first step. If any of the random account names match legitimate domain accounts, it indicates a targeted attack and possible credential compromise. Even if no failures are logged, a successful authentication might have been recorded separately. This investigation guides subsequent containment and remediation.

  • Run a full antivirus scan on the domain controller.

    Why it's wrong here

    An antivirus scan is not warranted at this point. The logs indicate an authentication attack, not malware activity. Scanning the domain controller would divert resources from addressing the immediate threat and would not prevent the ongoing logon attempts.

  • Notify the company's legal department for law enforcement involvement.

    Why it's wrong here

    Legal involvement and reporting to law enforcement may be appropriate later, but it is premature before confirming that the attack is successful or that sensitive data has been accessed. The analyst should first investigate and contain the threat.

    When this WOULD be correct

    This would be correct if the question stated that the brute force attack successfully compromised a privileged account and sensitive data was exfiltrated, requiring legal notification for regulatory compliance or criminal investigation.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Investigate whether any of the attempted accounts correspond to actual domain users.Correct answer

Why this is correct

This is the correct first step. If any of the random account names match legitimate domain accounts, it indicates a targeted attack and possible credential compromise. Even if no failures are logged, a successful authentication might have been recorded separately. This investigation guides subsequent containment and remediation.

Immediately block the IP address at the perimeter firewall.Wrong answer — click to see why

Why this is wrong here

Blocking the IP immediately is premature without confirming the threat; the failed logins use random account names, suggesting a password spray or reconnaissance, but legitimate users might be affected if the IP is shared or spoofed.

★ When this WOULD be the correct answer

In a scenario where the SOC analyst has confirmed that the source IP is a known malicious C2 server actively exploiting a critical vulnerability (e.g., EternalBlue) and causing system compromise, immediate blocking at the firewall is the correct containment step.

Why candidates choose this

Candidates often default to blocking as a quick fix, but fail to consider that the incident response process requires investigation first to avoid disrupting legitimate traffic and to gather evidence.

Notify the company's legal department for law enforcement involvement.Wrong answer — click to see why

Why this is wrong here

Notifying legal/law enforcement is premature at this stage; the analyst first needs to determine if the failed logons pose an actual threat (e.g., successful brute force or valid account compromise) before escalating.

★ When this WOULD be the correct answer

This would be correct if the question stated that the brute force attack successfully compromised a privileged account and sensitive data was exfiltrated, requiring legal notification for regulatory compliance or criminal investigation.

Why candidates choose this

Candidates may think that any external attack from a foreign IP warrants immediate legal involvement, overlooking the need for initial investigation and incident triage.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.