Courseiva
Security OperationseasyMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A user reports a suspicious pop-up on a workstation and the SOC suspects malware. Which action should the responder take first to contain the threat?

⚠ Common exam trap

CompTIA often tests the misconception that immediate eradication (wiping) is the first step, but the correct order is containment first to stop the spread, then eradication and recovery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disconnect the workstation from the network

Disconnecting the workstation from the network immediately isolates the suspected malware, preventing it from communicating with command-and-control (C2) servers, spreading laterally to other hosts, or exfiltrating data. This is the first step in the NIST incident response containment phase, as it stops network-based propagation without destroying forensic evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disconnect the workstation from the network

    Why this is correct

    Disconnecting the workstation from the network is the immediate containment step in incident response. It severs the host's ability to communicate with any command-and-control (C2) infrastructure, preventing the malware from receiving instructions, exfiltrating data, or using the host to pivot and move laterally to other systems. Unlike disruptive actions, isolation preserves the current state of memory and disk, allowing forensic evidence to be collected intact while stopping the attack's spread.

  • Wipe the workstation immediately

    Why it's wrong here

    Wiping the workstation immediately destroys all digital evidence that might be needed for a proper forensic investigation, including malware binaries, configuration artifacts, memory dumps, and logs that could reveal the attack vector or persistence mechanism. It also ignores the possibility that the malware has already propagated to other hosts, leaving those systems compromised while the initial evidence is erased. In incident response, eradication should only follow a careful evidence collection and analysis phase, so wiping is an unrecoverable and premature action.

  • Return the workstation to the user after restarting it

    Why it's wrong here

    Restarting the workstation does not remediate an active compromise; many types of malware are memory-resident and will simply relaunch on boot, while others use persistence mechanisms such as registry run keys or scheduled tasks that survive a restart. Returning the device to the user after a restart also fails to address the root cause, and continuing normal user activity could trigger additional spread, further data loss, or interfere with any volatile memory evidence that would be lost during the reboot. A controlled containment and investigation must occur before any system is returned to production.

  • Wait until the next patch cycle to see if the issue disappears

    Why it's wrong here

    Waiting until the next patch cycle assumes the pop-up is related to a known software vulnerability that can be fixed later, but the pop-up indicates an active security incident that requires immediate handling. Patching is a proactive measure against known vulnerabilities and does nothing to stop active exploitation, neutralize an already-installed backdoor, or prevent ongoing data exfiltration. The delay gives the attacker more time to spread laterally, gain persistence, and exfiltrate sensitive data, significantly increasing the impact of the compromise compared to immediate containment.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.