SY0-701 Security Operations Practice Question
Exhibit
EDR Alert Summary Host: FIN-LT-22 Severity: High Detection: Suspicious PowerShell with encoded command Parent Process: winword.exe Network Activity: outbound connection to 203.0.113.77:4444 User Note: 'The laptop is running very slowly and pop-ups started after opening an attachment.'
Based on the exhibit, what should the analyst do next to limit the impact of the suspected compromise?
⚠ Common exam trap
Candidates often choose to run an antivirus scan first (Option A) because they assume detection must precede containment, but the SY0-701 exam emphasizes that containment is the immediate priority to limit impact, even before identifying the specific malware.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate FIN-LT-22 from the network to contain the suspected malware activity.
Isolating FIN-LT-22 from the network immediately stops the suspected malware from communicating with command-and-control servers or spreading laterally to other hosts. This containment step aligns with the NIST incident response framework's containment phase, which prioritizes limiting damage before eradication or recovery. In a suspected compromise, network isolation (e.g., disabling the switch port or using a host-based firewall rule) is the fastest way to cut off malicious traffic without destroying volatile evidence in memory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan first and wait for the results before taking any other action.
Why it's wrong here
A full antivirus scan is a time-consuming process that does nothing to halt an active infection while it runs. At this stage, the threat may still be beaconing to its C2 server or attempting lateral movement, and the scan could miss fileless or polymorphic malware. Incident response prioritizes containment before eradication, so waiting for scan results only gives the attacker more time.
- ✓
Isolate FIN-LT-22 from the network to contain the suspected malware activity.
Why this is correct
Network isolation is the best immediate containment step when an endpoint shows signs of active malicious behavior. It limits further command-and-control traffic, prevents lateral movement, and buys time for investigation. In incident response, containment comes before eradication and recovery when the threat is still active.
- ✗
Reboot the laptop to clear the malicious process from memory.
Why it's wrong here
Rebooting will clear volatile memory but fails to disrupt persistence mechanisms such as scheduled tasks, services, or startup registry keys that reload the malware after boot. It also destroys volatile evidence—active network connections, process memory, and artifacts—critical for forensic analysis. In an active incident, powering down or rebooting should happen only after memory is captured, not as a first response.
- ✗
Reset the user's password and close the ticket after confirming they can log in again.
Why it's wrong here
Resetting the password addresses stolen credentials but does not remove or contain the malware already executing on FIN-LT-22. The attacker may maintain access through a backdoor, a separate local account, or a remote implant that ignores updated passwords. Closing the ticket after a login check ignores the active infection and risks leaving a foothold for future compromise.
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Firewall rule
A firewall rule is a set of conditions that tells a firewall which network traffic to allow or block based on attributes like source, destination, port, and protocol.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.