Correct answer & explanation
✓Isolation: Preventing the spread of the incident to other systems.
Incident response actions are sequenced to contain, preserve, analyze, remove, and learn from the incident. Isolating prevents spread; volatile data capture is time-sensitive; imaging preserves evidence; log analysis reveals details; eradication cleans the system; lessons learned improve processes.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
How Courseiva writes practice questions · Editorial policy
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Select all options that correctly match each incident response activity to the phase of the incident response lifecycle it best represents.
1. A SOC analyst disables a compromised account, isolates the workstation from the network, and preserves volatile evidence.
2. The team images the infected system, removes the malicious persistence mechanism, and patches the exploited vulnerability.
3. After restoring services, the team reviews timeline gaps, detection delays, and control failures with management.
4. Before the attack occurs, the team verifies contact lists, playbooks, escalation paths, and backup credentials.
5. The team confirms suspicious authentication logs, endpoint alerts, and unusual outbound traffic indicate an active compromise.
hard- ✓ A.Preparation: Verifying contact lists, playbooks, escalation paths, and backup credentials before an attack.
- ✓ B.Detection and Analysis: Confirming suspicious logs, endpoint alerts, and unusual outbound traffic indicate an active compromise.
- ✓ C.Containment, Eradication, Recovery: Disabling compromised accounts, isolating workstations, imaging systems, removing persistence, and patching vulnerabilities.
- ✓ D.Post-Incident Activity: Reviewing timeline gaps, detection delays, and control failures with management after restoring services.
- E.Preparation: A SOC analyst disables a compromised account, isolates the workstation, and preserves volatile evidence.
- F.Detection and Analysis: The team images the infected system, removes the malicious persistence mechanism, and patches the exploited vulnerability.
Why A: Activities 1 and 2 both fall under Containment, Eradication, and Recovery as they involve immediate response and remediation. Activity 3 is Post-Incident Activity, focusing on lessons learned. Activity 4 is Preparation, done before an incident. Activity 5 is Detection and Analysis, confirming an incident.