Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

At 10:15, a file server begins renaming documents and creating payment notes. The SOC confirms the server is also making SMB connections to other internal hosts, but users can still access shared folders. What should the incident handler do FIRST?

⚠ Common exam trap

Many exam-takers choose to shut down the server (Option B) thinking it stops the attack, but CompTIA emphasizes preserving power and evidence for forensic analysis, making isolation the correct first step.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disconnect the server from the network or isolate it through EDR containment while preserving power

The correct first step is to contain the incident by disconnecting the server from the network or using EDR containment while preserving power. This stops the spread of malicious SMB connections and prevents further damage, while keeping the system powered on to preserve volatile evidence (e.g., memory, running processes) for forensic analysis. Immediate containment aligns with the NIST incident response framework's containment phase, prioritizing isolation over eradication or recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disconnect the server from the network or isolate it through EDR containment while preserving power

    Why this is correct

    Network isolation or EDR containment is the correct immediate step because it halts ransomware's further encryption and lateral movement while keeping the system powered on. Preserving power retains volatile evidence—RAM, active network connections, and running processes—which incident responders need for forensic analysis and recovery. This approach balances rapid containment with the integrity of digital evidence, unlike destructive shutdowns or premature restoration.

  • Shut down the server immediately to stop all malicious activity

    Why it's wrong here

    Shutting down the server immediately stops the visible malicious activity but discards volatile evidence from memory, such as encryption keys, running malware processes, and open network connections. A hard power-off may also corrupt the file system and trigger self-protection mechanisms that destroy more artifacts. Incident response favors isolation over shutdown because a live system allows forensic imaging and analysis that can identify the ransomware strain and support decryption—critical for minimizing data loss.

  • Restore the server from backup before taking any other action

    Why it's wrong here

    Restoring from backup before containing the threat leaves the root cause active; the malware or attacker will simply re-encrypt restored files, and the process may overwrite the very evidence needed to identify the entry vector. Early restoration can also use a backup that itself is compromised, reintroducing the infection. Proper order is to isolate the server first, then collect forensics, and only then restore from clean backups after confirming the source is neutralized.

  • Wait for users to report more symptoms before responding

    Why it's wrong here

    Waiting for user reports sacrifices the golden hours of containment, allowing ransomware to spread across the network, encrypt additional shares, and reach backup systems. Attackers move quickly and lateral movement may be silent; by the time users notice, the blast radius has expanded exponentially. Incident response requires proactive monitoring and immediate alert triage—not passive observation—to contain the threat while it is still localized.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.