Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A workstation suddenly begins making SMB connections to many internal servers within a few minutes. What is the best immediate response?

⚠ Common exam trap

Test-takers frequently think SMB traffic is always benign because it is a legitimate protocol, failing to recognize that a sudden spike in SMB connections to multiple internal servers is a red flag for active lateral movement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate the workstation from the network for containment.

The workstation's sudden SMB connections to many internal servers strongly indicate compromise, such as ransomware or worm propagation. Isolating the workstation immediately contains the threat, preventing lateral movement and further damage while preserving forensic evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Allow the traffic because SMB is a normal file-sharing protocol.

    Why it's wrong here

    SMB is indeed a standard protocol for file sharing on Windows networks, but a workstation suddenly making SMB connections to many different hosts is not normal baseline behavior. This pattern often signals automated lateral movement or malware propagation, such as a worm attempting to spread via SMB vulnerabilities. Allowing the traffic without investigation would permit potential malicious activity to continue, possibly infecting other systems, so it cannot be justified simply because SMB is legitimate.

  • Isolate the workstation from the network for containment.

    Why this is correct

    Isolating the workstation from the network is the correct first response because it immediately contains the suspicious activity and prevents the host from reaching other systems, which limits lateral movement and the blast radius of a possible compromise. This preserves the ability to inspect traffic and run forensics without the risk of in-flight attacks. In incident response, containment is prioritized before any remediation or eradication steps, making this the safest choice.

  • Delete the local event logs to reduce alert noise.

    Why it's wrong here

    Deleting local event logs would destroy crucial forensic evidence, potentially violating chain of custody requirements, and it does nothing to stop the ongoing SMB connections. Logs are essential for identifying the initial infection vector, the scope of compromise, and other affected hosts, so tampering with them would severely hamper the investigation. Furthermore, an attacker might have already cleared or altered logs, and deleting more would only compound the problem while failing to address the immediate security threat.

  • Disable all SMB services on every server immediately.

    Why it's wrong here

    Disabling all SMB services on every server is a drastic, organization-wide action that would cause significant business disruption and likely impact legitimate file-sharing operations. This approach is too broad for initial containment because the goal at this stage is to isolate the single suspicious workstation, not to disable a core protocol across the entire environment. A more measured response would involve selective blocking or firewall rules after investigation, ensuring that only necessary SMB traffic is affected while preserving business continuity.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.