Courseiva
Security OperationseasyMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

An EDR alert shows a user workstation launching an unfamiliar executable from the Downloads folder and then making repeated outbound connections to an IP address in another country. What is the best first response by the security team?

⚠ Common exam trap

A common mix-up: candidates confuse incident response phases (e.g., jumping to eradication or recovery before containment) or think that disabling the user account is sufficient, when in fact the running process must be contained first to stop active network communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate the workstation from the network and begin incident triage

Isolating the workstation from the network immediately stops the potential command-and-control (C2) communication and prevents lateral movement, which is the priority first response in incident triage. The EDR alert indicates a suspicious executable from the Downloads folder making repeated outbound connections to a foreign IP, which strongly suggests malware or a trojan. Isolating the host preserves volatile evidence (e.g., memory, network connections) for forensic analysis while containing the threat.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Wait for more alerts before taking any action to avoid disrupting the user

    Why it's wrong here

    Adopting a passive wait-and-see posture is dangerous because the EDR alert already indicates a potential compromise. Each minute the workstation remains on the network allows an adversary to install persistence, move laterally, or exfiltrate sensitive data. Incident response principles require immediate containment upon a validated alert, not waiting for more alerts, which would only expand the scope of the incident and increase remediation costs.

  • Isolate the workstation from the network and begin incident triage

    Why this is correct

    Network isolation is the correct first response because it immediately severs the attacker's ability to maintain command-and-control or reach other hosts, containing the blast radius. Unlike destructive actions, isolation preserves volatile evidence (memory, running processes) and non-volatile artifacts for proper forensic triage. This action aligns with NIST SP 800-61 containment strategies and gives the incident response team a controlled environment to investigate without the threat continuing to propagate.

  • Immediately reinstall the operating system without collecting evidence

    Why it's wrong here

    Reinstalling the OS without collecting forensic evidence destroys the very artifacts needed to determine the root cause and scope of the intrusion. Memory dumps, disk images, logs, and prefetch files may reveal the initial access vector, attacker tools, and lateral movement techniques. Early reimaging also fails to address threats like firmware implants that survive reinstallation, and it forfeits the opportunity for intelligence to improve defenses and prevent future incidents.

  • Disable the user's account in the directory service and close the ticket

    Why it's wrong here

    Disabling the user account in the directory service only prevents future interactive logons but has no effect on a malicious process already running under that user's context. It does not terminate the process, block the host's network communications, or remove persistence mechanisms, so the compromise remains active. Closing the ticket prematurely also ignores the need for endpoint containment and forensic investigation, leaving other systems at risk.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.