Courseiva
Security OperationseasyMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

After a phishing account compromise has been contained and the attacker’s mailbox forwarding rule was removed, what should the team do next?

⚠ Common exam trap

Many candidates assume removing the visible persistence mechanism (the forwarding rule) is sufficient, but CompTIA tests the understanding that attackers often deploy multiple backdoors, and credential reset plus full verification is mandatory before recovery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Reset credentials and verify there are no other persistence methods before recovery.

After removing a mailbox forwarding rule, the team must reset the compromised account's credentials and verify that no other persistence mechanisms (e.g., additional forwarding rules, OAuth app grants, or mailbox delegation) remain. This ensures the attacker cannot regain access using cached credentials or alternate backdoors, which is critical before returning the account to production.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Stop the investigation because the forwarding rule was deleted.

    Why it's wrong here

    Deleting the forwarding rule is only a containment action, not eradication. The attacker may have created additional persistence mechanisms such as mailbox delegation, transport rules, or malware implants, and the compromised account's credentials are still in the attacker's hands. Stopping the investigation leaves those threats active and risks a rapid re-infection.

  • Reset credentials and verify there are no other persistence methods before recovery.

    Why this is correct

    This option follows the eradication and recovery phases of incident response. Resetting the compromised account's credentials revokes the attacker's direct access, and verifying for other persistence methods (e.g., additional forwarding rules, new admin roles, or scheduled tasks) ensures the intrusion is fully removed before restoring services. It avoids an incomplete recovery that could allow the attacker to slip back in.

  • Close the ticket and tell the user to be more careful next time.

    Why it's wrong here

    Closing the ticket without further action ignores the fact that the compromise is an active security incident, not a user training issue. The attacker likely maintained access through multiple means beyond the forwarding rule, and telling the user to be careful does not revoke that access or remediate any backdoors. This skips critical eradication and recovery steps, leaving the organization exposed.

  • Wait one week before taking any action so the attacker does not notice.

    Why it's wrong here

    Delaying the response for a week gives the attacker a long window to continue monitoring email, exfiltrate sensitive data, or re-establish persistence through other means. Incident response best practices mandate immediate containment and eradication to minimize dwell time and damage. A wait-and-see approach contradicts the urgency required after a confirmed account compromise.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.