SY0-701 Security Operations Practice Question
After containment and eradication of malware on several laptops, the team restores the devices from known-good images and verifies that users can authenticate and access email. Which action should occur NEXT to complete the incident response lifecycle and reduce future impact?
⚠ Common exam trap
Many candidates assume the incident response lifecycle ends once systems are restored and operational, overlooking the mandatory post-incident activity phase that ensures continuous improvement and prevents recurrence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a lessons-learned review and update playbooks, controls, or detections based on the incident
The incident response lifecycle includes a post-incident activity phase where the team conducts a lessons-learned review to identify gaps in security controls, update playbooks, and improve detection signatures. This step ensures that the organization reduces the likelihood and impact of similar incidents in the future, completing the lifecycle beyond just restoring operations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Close the ticket immediately because the systems are working again
Why it's wrong here
Closing the ticket when systems appear functional prematurely ends the incident response lifecycle. Normal operation does not guarantee that the malware's root cause, such as an unpatched vulnerability or compromised credential, has been eliminated. The response phase must include verification of eradication, identification of indicators of compromise (IOCs), and appropriate reporting to stakeholders before closure is considered. Skipping these steps can allow the same threat to re-emerge.
- ✓
Perform a lessons-learned review and update playbooks, controls, or detections based on the incident
Why this is correct
A lessons-learned review is the formal post-incident activity in the NIST and SANS incident response frameworks. It examines what worked, what failed, and which detection rules, playbooks, or security controls need adjustment, turning the incident into actionable intelligence. Updating playbooks and detections based on the observed TTPs (tactics, techniques, and procedures) reduces recurrence and improves response time for future incidents. This is the correct step because it captures continuous improvement rather than merely restoring service.
- ✗
Reimage the laptops again even though they were already restored and tested
Why it's wrong here
Reimaging a laptop that has already been restored and validated as clean is redundant effort without a technical justification. If the system was reimaged from a known-good source and then scanned or tested for indicators of compromise, repeating the same action adds no security value. The real gap is likely in the broader environment, such as the initial attack vector or insufficient endpoint detection, which reimaging alone will not fix. The response should focus on systemic improvements, not repetitive remediation.
- ✗
Disable all email access for the organization until the next quarterly meeting
Why it's wrong here
Disabling all email organization-wide is a disproportionate and unfocused containment action that seriously harms business operations while failing to address the specific malware delivery mechanism. Email is likely the vector, but a blanket outage does not identify malicious senders, quarantine suspicious messages, or revoke compromised credentials. Targeted containment—such as blocking malicious domains, applying mailbox rules, requiring reauthentication, and segmenting affected accounts—is both safer and more effective. Additionally, waiting until the next quarterly meeting leaves the organization exposed for an unacceptable period.
Go deeper
Related to this question
Learn chapter
Identity and Access Management
Key term
Incident response lifecycle
The Incident response lifecycle is the structured process organizations follow to detect, contain, eradicate, and recover from cybersecurity incidents while learning from each event to improve future defenses.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.