SY0-701 Security Operations Practice Question
After a phishing account compromise has been contained and the attacker’s mailbox forwarding rule was removed, what should the team do next?
⚠ Common exam trap
Many candidates assume removing the visible persistence mechanism (the forwarding rule) is sufficient, but CompTIA tests the understanding that attackers often deploy multiple backdoors, and credential reset plus full verification is mandatory before recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reset credentials and verify there are no other persistence methods before recovery.
After removing a mailbox forwarding rule, the team must reset the compromised account's credentials and verify that no other persistence mechanisms (e.g., additional forwarding rules, OAuth app grants, or mailbox delegation) remain. This ensures the attacker cannot regain access using cached credentials or alternate backdoors, which is critical before returning the account to production.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stop the investigation because the forwarding rule was deleted.
Why it's wrong here
Deleting the forwarding rule is only a containment action, not eradication. The attacker may have created additional persistence mechanisms such as mailbox delegation, transport rules, or malware implants, and the compromised account's credentials are still in the attacker's hands. Stopping the investigation leaves those threats active and risks a rapid re-infection.
- ✓
Reset credentials and verify there are no other persistence methods before recovery.
Why this is correct
This option follows the eradication and recovery phases of incident response. Resetting the compromised account's credentials revokes the attacker's direct access, and verifying for other persistence methods (e.g., additional forwarding rules, new admin roles, or scheduled tasks) ensures the intrusion is fully removed before restoring services. It avoids an incomplete recovery that could allow the attacker to slip back in.
- ✗
Close the ticket and tell the user to be more careful next time.
Why it's wrong here
Closing the ticket without further action ignores the fact that the compromise is an active security incident, not a user training issue. The attacker likely maintained access through multiple means beyond the forwarding rule, and telling the user to be careful does not revoke that access or remediate any backdoors. This skips critical eradication and recovery steps, leaving the organization exposed.
- ✗
Wait one week before taking any action so the attacker does not notice.
Why it's wrong here
Delaying the response for a week gives the attacker a long window to continue monitoring email, exfiltrate sensitive data, or re-establish persistence through other means. Incident response best practices mandate immediate containment and eradication to minimize dwell time and damage. A wait-and-see approach contradicts the urgency required after a confirmed account compromise.
Go deeper
Related to this question
Learn chapter
Identity and Access Management
Key term
OAuth
OAuth is an open standard for access delegation that allows users to grant third-party applications limited access to their resources without sharing their credentials.
Key term
Persistence
Persistence is the set of techniques attackers use to maintain long-term access to a compromised system even after reboots or credential changes.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.