Courseiva
Security OperationseasyMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

Exhibit

EDR Alert Summary
Host: FIN-LT-22
Severity: High
Detection: Suspicious PowerShell with encoded command
Parent Process: winword.exe
Network Activity: outbound connection to 203.0.113.77:4444
User Note: 'The laptop is running very slowly and pop-ups started after opening an attachment.'

Based on the exhibit, what should the analyst do next to limit the impact of the suspected compromise?

⚠ Common exam trap

Candidates often choose to run an antivirus scan first (Option A) because they assume detection must precede containment, but the SY0-701 exam emphasizes that containment is the immediate priority to limit impact, even before identifying the specific malware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate FIN-LT-22 from the network to contain the suspected malware activity.

Isolating FIN-LT-22 from the network immediately stops the suspected malware from communicating with command-and-control servers or spreading laterally to other hosts. This containment step aligns with the NIST incident response framework's containment phase, which prioritizes limiting damage before eradication or recovery. In a suspected compromise, network isolation (e.g., disabling the switch port or using a host-based firewall rule) is the fastest way to cut off malicious traffic without destroying volatile evidence in memory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Run a full antivirus scan first and wait for the results before taking any other action.

    Why it's wrong here

    A full antivirus scan is a time-consuming process that does nothing to halt an active infection while it runs. At this stage, the threat may still be beaconing to its C2 server or attempting lateral movement, and the scan could miss fileless or polymorphic malware. Incident response prioritizes containment before eradication, so waiting for scan results only gives the attacker more time.

  • Isolate FIN-LT-22 from the network to contain the suspected malware activity.

    Why this is correct

    Network isolation is the best immediate containment step when an endpoint shows signs of active malicious behavior. It limits further command-and-control traffic, prevents lateral movement, and buys time for investigation. In incident response, containment comes before eradication and recovery when the threat is still active.

  • Reboot the laptop to clear the malicious process from memory.

    Why it's wrong here

    Rebooting will clear volatile memory but fails to disrupt persistence mechanisms such as scheduled tasks, services, or startup registry keys that reload the malware after boot. It also destroys volatile evidence—active network connections, process memory, and artifacts—critical for forensic analysis. In an active incident, powering down or rebooting should happen only after memory is captured, not as a first response.

  • Reset the user's password and close the ticket after confirming they can log in again.

    Why it's wrong here

    Resetting the password addresses stolen credentials but does not remove or contain the malware already executing on FIN-LT-22. The attacker may maintain access through a backdoor, a separate local account, or a remote implant that ignores updated passwords. Closing the ticket after a login check ignores the active infection and risks leaving a foothold for future compromise.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.