Courseiva
Security OperationsmediumMatchingObjective-mapped

SY0-701 Security Operations Practice Question

Match each incident response action to its primary purpose during a suspected endpoint compromise.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Contain the incident and limit spread to other systems

Preserve evidence that could disappear after power-off

Eradicate persistence and return the system to a trusted state

Recover business operations and return service to normal

Complete lessons learned and improve future response

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolation: Preventing the spread of the incident to other systems.

Incident response actions are sequenced to contain, preserve, analyze, remove, and learn from the incident. Isolating prevents spread; volatile data capture is time-sensitive; imaging preserves evidence; log analysis reveals details; eradication cleans the system; lessons learned improve processes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Isolation: Preventing the spread of the incident to other systems.

    Why this is correct

    Isolation is a containment strategy that severs the compromised system's network connectivity, disables unnecessary services, and may involve network segmentation or firewall rules to stop lateral movement. The primary goal is to limit the blast radius and prevent the attacker from accessing other systems or exfiltrating data, while preserving the system for further forensic analysis. Unlike eradication, which removes the threat, isolation is purely about containment and maintaining a safe perimeter for investigation.

  • Volatile Data Capture: Preserving evidence that may be lost if the system is powered off or rebooted.

    Why this is correct

    Volatile data capture involves collecting information that resides in RAM and other transient storage, such as running processes, open network connections, logged-in users, and encryption keys, which is irretrievably lost when power is removed. Because memory contents vanish on shutdown or reboot, forensic responders must perform this capture as a high-priority step before any power-down. This preserves time-sensitive evidence that is often critical for understanding the attacker's current activities and in-memory malware.

  • Imaging: Creating a bit-for-bit copy of the affected drive for forensic analysis.

    Why this is correct

    Imaging, also known as forensic imaging, creates a bit-for-bit copy (often a raw or E01 format file) of the entire storage device, including deleted files, unallocated space, and slack space. This exact replica allows analysts to perform thorough forensic examination without altering the original evidence, thereby maintaining the chain of custody and data integrity through hashing. It is a non-destructive procedure that captures the complete state of the storage medium for offline analysis, distinct from volatile memory capture.

  • Isolation: Removing malicious files from the system.

    Why it's wrong here

    Removing malicious files is an eradication activity, not isolation. Isolation focuses on containment—cutting off the system's access to the network and other resources—whereas eradication involves actively deleting malware, disabling adversary accounts, and patching vulnerabilities. While isolation may prepare a system for eradication, the action of file removal itself is part of the remediation phase and does not address the immediate goal of preventing spread.

  • Volatile Data Capture: Creating a forensic copy of the hard drive.

    Why it's wrong here

    Creating a forensic copy of the hard drive is the definition of disk imaging, not volatile data capture. Volatile data capture specifically targets transient data stored in memory (RAM), like running processes and network sessions, which disappears upon power-off. Imaging preserves the non-volatile data on persistent storage and does not capture the live system state, making it a separate and complementary step in the forensic process.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Select all options that correctly match each incident response activity to the phase of the incident response lifecycle it best represents. 1. A SOC analyst disables a compromised account, isolates the workstation from the network, and preserves volatile evidence. 2. The team images the infected system, removes the malicious persistence mechanism, and patches the exploited vulnerability. 3. After restoring services, the team reviews timeline gaps, detection delays, and control failures with management. 4. Before the attack occurs, the team verifies contact lists, playbooks, escalation paths, and backup credentials. 5. The team confirms suspicious authentication logs, endpoint alerts, and unusual outbound traffic indicate an active compromise.

hard
  • A.Preparation: Verifying contact lists, playbooks, escalation paths, and backup credentials before an attack.
  • B.Detection and Analysis: Confirming suspicious logs, endpoint alerts, and unusual outbound traffic indicate an active compromise.
  • C.Containment, Eradication, Recovery: Disabling compromised accounts, isolating workstations, imaging systems, removing persistence, and patching vulnerabilities.
  • D.Post-Incident Activity: Reviewing timeline gaps, detection delays, and control failures with management after restoring services.
  • E.Preparation: A SOC analyst disables a compromised account, isolates the workstation, and preserves volatile evidence.
  • F.Detection and Analysis: The team images the infected system, removes the malicious persistence mechanism, and patches the exploited vulnerability.

Why A: Activities 1 and 2 both fall under Containment, Eradication, and Recovery as they involve immediate response and remediation. Activity 3 is Post-Incident Activity, focusing on lessons learned. Activity 4 is Preparation, done before an incident. Activity 5 is Detection and Analysis, confirming an incident.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.