Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

EDR alerts on a remote laptop show a suspicious process attempting to dump browser credentials and then contacting a rare domain. The user is in another time zone and still needs the laptop online for a presentation later today. What containment action is best?

⚠ Common exam trap

Candidates often choose to wait until after the presentation (Option C) due to business continuity concerns, failing to recognize that immediate containment via network isolation can preserve both security and productivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Remotely isolate the device through the EDR console while keeping it powered on.

Remotely isolating the device through the EDR console is the best containment action because it immediately blocks all network communication to and from the laptop while keeping it powered on and running. This prevents the suspicious process from exfiltrating browser credentials or communicating with the rare command-and-control domain, yet allows the user to continue using local applications for the presentation later today. EDR isolation typically works by applying a host-based firewall rule that drops all traffic except to the EDR management server, ensuring the threat is contained without disrupting local productivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Remotely isolate the device through the EDR console while keeping it powered on.

    Why this is correct

    EDR isolation is the best containment action because it stops most network communication while preserving the device state for investigation. Keeping the endpoint powered on maintains access to volatile evidence and avoids unnecessary disruption to disk contents or running processes. This is especially useful when the user is remote, because it can contain the threat quickly without requiring physical access or a full shutdown that would erase useful forensic data.

  • Ask the user to uninstall the EDR agent and reboot the laptop.

    Why it's wrong here

    Uninstalling the EDR agent strips away the only active sensor providing telemetry and forensic detail, converting a managed endpoint into a blind spot for the security operations team. A reboot also discards volatile memory evidence, such as loaded modules, network connections, and injected code, which may allow a persistent threat to survive on disk and relaunch undetected. Furthermore, the user may lack privileges to remove the agent, and some EDR products implement tamper protection that actively resists uninstallation, making the request futile and counterproductive.

  • Wait until after the presentation and then begin containment.

    Why it's wrong here

    Delaying containment to accommodate a presentation directly extends the attacker's dwell time on the remote laptop, granting more opportunities for privilege escalation, lateral movement, or continuous data exfiltration to command-and-control infrastructure. Modern threats often operate on active timelines, and even a short postponement can allow the malware to persist, spread to mapped drives, or deploy crypto-ransomware before the user even finishes their slides. Incident response prioritizes swift isolation over business convenience because every minute of delay lowers the chance of containing the breach without broader network damage.

  • Email the user asking them to close the browser and log out of their accounts.

    Why it's wrong here

    Instructing the user to close the browser and log out of accounts assumes the suspicious process is web-based and user-initiated, but the EDR alert indicates a distinct executable that may be injected into the browser, running as a separate service, or already delivering payloads outside the browser session. Email is a slow, asynchronous channel, and a remote user may not see the request immediately, while the malware continues to communicate over the network regardless of browser state. Logging out does not terminate system-level processes or clear persistent registry keys, so the threat remains active and under the attacker's control.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.