Courseiva
Security OperationseasyMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

After a phishing incident, the security team wants to preserve evidence for later review. Which action is most appropriate?

⚠ Common exam trap

A common mix-up: candidates think deleting or forwarding the email is a quick fix to prevent further harm, but the exam emphasizes that evidence preservation (via capture of headers and content) is the first priority in incident response, not containment or notification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Capture and save the email headers and message content

Preserving the email headers and message content is essential for forensic analysis. Email headers contain routing information, including the originating IP address, authentication results (SPF, DKIM, DMARC), and timestamps, which are critical for tracing the source of the phishing attack and understanding the attack vector. Deleting or forwarding the email would destroy this evidence, compromising the investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Have the user delete the phishing email to avoid further exposure

    Why it's wrong here

    Deleting the email destroys the original artifact, including the full RFC 5322 headers, metadata, and message body, which are essential for tracing the delivery path via each 'Received' hop and for identifying sender infrastructure. Without the raw message, investigators lose the ability to extract embedded URLs, attachments, and other indicators of compromise, and any forensic chain of custody is broken. Even moving it to the Trash folder may not preserve the message in an intact, forensically sound format, especially if retention policies auto-purge or if the mailbox is accessed by the user afterward.

  • Capture and save the email headers and message content

    Why this is correct

    Preserving the raw email as an .eml or .msg file, or exporting the full message with headers from the web client, gives investigators a complete, immutable artifact for analysis. The 'Received' header chains can be traced back to the originating IP and MTA path, while SPF, DKIM, and DMARC authentication results in the headers reveal whether the message was spoofed or sent from a compromised legitimate account. The message content is also vital for extracting malicious links, attachments, and other Indicators of Compromise (IOCs) and for providing the full payload context needed for detection rule creation and user awareness training.

  • Forward the email to every employee as a warning

    Why it's wrong here

    Forwarding the original email to all employees risks spreading the malicious payload, because users may click embedded links or open attachments, thereby expanding the incident and undermining containment. Any forward operation also strips or rewrites the original message headers, irreparably altering the forensic evidence and preventing an accurate delivery-path reconstruction. Furthermore, a mass-forward of a live phishing email creates confusion and panic rather than a clear, security-team-vetted warning, which would instead be a generic message with no direct links or attachment from the original email.

  • Change the user's office seat assignment immediately

    Why it's wrong here

    Changing the user's office seat assignment is a physical move that does not preserve any electronic evidence and has no bearing on the technical details of the phishing incident. The correct incident-response priority is to isolate the compromised workstation from the network and preserve the mailbox content, audit logs, and click-traffic metadata; moving the user's seat is operationally disruptive and can even hamper the response by misassociating the user with the wrong machine or network segment. This action neither captures evidence nor mitigates the underlying threat, so it is irrelevant to the forensic preservation objective.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.