Courseiva
Threats, Vulnerabilities, and MitigationsmediumMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A user's laptop suddenly shows encrypted .docx files, a ransom note, and the EDR console reports mass file renames and shadow copy deletion. The device is still online and connected to the corporate VPN. What is the best immediate action?

⚠ Common exam trap

Test-takers frequently choose to restore from backups (Option C) first, not realizing that the infected host must be isolated before any recovery attempt to prevent immediate re-encryption of restored files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Quarantine the endpoint from the network through EDR or physical isolation.

The immediate priority in a confirmed ransomware incident is to contain the threat by isolating the compromised host from the network. The EDR console showing mass file renames and shadow copy deletion indicates active encryption and lateral movement risk. Quarantining via EDR or physically disconnecting the network cable stops the ransomware from encrypting additional shares or communicating with its C2 server, preserving evidence and preventing further damage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Reboot the laptop into safe mode and attempt manual malware removal.

    Why it's wrong here

    This may destroy useful volatile evidence and does not stop active spread quickly enough.

  • Quarantine the endpoint from the network through EDR or physical isolation.

    Why this is correct

    Isolating the system immediately contains the ransomware, limits lateral spread, and preserves the device for later investigation. Because the host is still connected to the VPN, it could continue encrypting mapped drives or reach other systems. Containment comes before eradication or recovery, especially when destructive behavior is still active.

  • Restore the affected files from backup before taking any other action.

    Why it's wrong here

    Recovery is important, but restoring too early can overwrite evidence and may fail if the threat is still active.

  • Tell the user to change their password and continue working from the same laptop.

    Why it's wrong here

    Password changes alone do not stop encryption activity or protect other connected systems from the ongoing compromise.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A file server suddenly renames documents with a new extension and displays a note demanding payment in cryptocurrency to restore access. What type of malware is most likely involved?

easy
  • A.Ransomware
  • B.Spyware
  • C.Worm
  • D.Rootkit

Why A: Ransomware is designed to encrypt files on a system, making them inaccessible, and then demand a ransom—typically in cryptocurrency—to restore access. The sudden renaming of documents with a new extension is a hallmark of ransomware encryption, as it appends a custom extension to indicate the files have been locked. The displayed note demanding payment confirms the extortion motive, which is unique to ransomware among the given options.

Variation 2. A user's workstation suddenly renames documents with a new extension, displays a ransom note, and blocks access to a shared drive. Which two indicators support ransomware? Select two.

easy
  • A.Files are renamed or encrypted and no longer open normally
  • B.A ransom note demands payment for decryption or restoration
  • C.The mouse pointer moves slowly after long idle periods
  • D.The browser homepage changed after a software update
  • E.A new USB keyboard is detected by the operating system

Why A: Ransomware typically encrypts files and renames them with a new extension (e.g., .encrypted, .locked), making them unopenable without the decryption key. This behavior directly matches the scenario where documents are renamed and access is blocked, confirming file encryption as a core indicator of ransomware.

Variation 3. A user's laptop starts renaming many documents, and a ransom note appears on the desktop. What is the best immediate action for the help desk to recommend?

easy
  • A.Shut down the laptop immediately and leave it on the desk.
  • B.Disconnect the laptop from the network to contain the infection.
  • C.Delete the ransom note and continue working until the next reboot.
  • D.Install a new browser extension to block the attacker.

Why B: Disconnecting the laptop from the network immediately stops the ransomware from communicating with its command-and-control (C2) server, preventing further encryption of network shares and lateral movement. This containment step is critical before any remediation, as it isolates the threat and preserves evidence for forensic analysis.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.