SY0-701 Security Operations Practice Question
A user reports a suspicious pop-up on a workstation and the SOC suspects malware. Which action should the responder take first to contain the threat?
⚠ Common exam trap
CompTIA often tests the misconception that immediate eradication (wiping) is the first step, but the correct order is containment first to stop the spread, then eradication and recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the workstation from the network
Disconnecting the workstation from the network immediately isolates the suspected malware, preventing it from communicating with command-and-control (C2) servers, spreading laterally to other hosts, or exfiltrating data. This is the first step in the NIST incident response containment phase, as it stops network-based propagation without destroying forensic evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disconnect the workstation from the network
Why this is correct
Disconnecting the workstation from the network is the immediate containment step in incident response. It severs the host's ability to communicate with any command-and-control (C2) infrastructure, preventing the malware from receiving instructions, exfiltrating data, or using the host to pivot and move laterally to other systems. Unlike disruptive actions, isolation preserves the current state of memory and disk, allowing forensic evidence to be collected intact while stopping the attack's spread.
- ✗
Wipe the workstation immediately
Why it's wrong here
Wiping the workstation immediately destroys all digital evidence that might be needed for a proper forensic investigation, including malware binaries, configuration artifacts, memory dumps, and logs that could reveal the attack vector or persistence mechanism. It also ignores the possibility that the malware has already propagated to other hosts, leaving those systems compromised while the initial evidence is erased. In incident response, eradication should only follow a careful evidence collection and analysis phase, so wiping is an unrecoverable and premature action.
- ✗
Return the workstation to the user after restarting it
Why it's wrong here
Restarting the workstation does not remediate an active compromise; many types of malware are memory-resident and will simply relaunch on boot, while others use persistence mechanisms such as registry run keys or scheduled tasks that survive a restart. Returning the device to the user after a restart also fails to address the root cause, and continuing normal user activity could trigger additional spread, further data loss, or interfere with any volatile memory evidence that would be lost during the reboot. A controlled containment and investigation must occur before any system is returned to production.
- ✗
Wait until the next patch cycle to see if the issue disappears
Why it's wrong here
Waiting until the next patch cycle assumes the pop-up is related to a known software vulnerability that can be fixed later, but the pop-up indicates an active security incident that requires immediate handling. Patching is a proactive measure against known vulnerabilities and does nothing to stop active exploitation, neutralize an already-installed backdoor, or prevent ongoing data exfiltration. The delay gives the attacker more time to spread laterally, gain persistence, and exfiltrate sensitive data, significantly increasing the impact of the compromise compared to immediate containment.
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.