Courseiva
Security OperationseasyMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A workstation is suspected of malware infection, and it is still powered on and connected to the network. Which action best preserves volatile evidence before the system is shut down?

⚠ Common exam trap

CompTIA often tests the misconception that immediate shutdown stops malware activity, but the trap here is that volatile evidence is lost on power-off, and the correct forensic priority is to capture memory and process data first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Capture memory and note running processes before taking further action.

Volatile evidence, such as the contents of RAM (running processes, network connections, open files), is lost when the system is powered off. Capturing a memory dump and recording running processes preserves this critical data for forensic analysis, allowing investigators to identify malware artifacts (e.g., injected code, hidden processes) that exist only in memory. This aligns with the NIST SP 800-86 forensic procedure of prioritizing volatile data collection before system shutdown.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Immediately power off the workstation to stop any malicious activity.

    Why it's wrong here

    Powering off a live system is an anti-forensic action: it destroys the very volatile evidence that incident responders need, such as RAM-resident malware, injected code, active network sockets, and running processes. Memory forensics can often reveal command-and-control activity, encryption keys, and process hollowing that would be permanently lost. The proper first step is to capture a memory image and record running processes, then follow an established order of volatility before any shutdown.

  • Capture memory and note running processes before taking further action.

    Why this is correct

    Volatile data such as memory, active network connections, and running processes can disappear if the system is powered down. Capturing that information first preserves evidence that may show malware behavior, injected code, or command-and-control activity. This is a core incident-response practice when the system is still live.

  • Run a full antivirus scan before documenting anything.

    Why it's wrong here

    Running a full antivirus scan on a suspicious live system alters the evidentiary state: the scan updates timestamps, quarantines or deletes files, and may trigger malware defenses that wipe artifacts or connect to an attacker. Moreover, modern malware can evade signature-based scanning while in memory, giving a false sense of security. Preservation must happen first—through memory and disk imaging—before any remediation tool touches the system.

  • Delete temporary files to reduce the chance of reinfection.

    Why it's wrong here

    Deleting temporary files at this stage destroys potential evidence such as dropped payloads, credential-stealing logs, or staged malware that may reside in temp directories. The action also changes file system metadata and can delete the very indicators of compromise needed to determine the infection vector. Containment via network isolation should come first, and any cleanup must wait until forensic copies are made and the investigation is complete.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.