Courseiva
Security OperationseasyMultiple SelectObjective-mapped

SY0-701 Security Operations Practice Question

A workstation is suspected of running malware and contacting an unknown host. Which two actions belong in the containment phase? Select two.

⚠ Common exam trap

Many candidates confuse the containment phase with the eradication phase, mistakenly thinking that reimaging (Option C) is a containment action when it is actually an eradication step that should only occur after evidence collection and analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate the workstation from the network.

Isolating the workstation from the network (A) immediately stops the malware's ability to communicate with the command-and-control (C2) server, preventing data exfiltration and further propagation. Blocking the malicious IP or domain at the firewall or proxy (B) is a containment action that prevents any system on the network from reaching the known malicious host, even if other hosts are already compromised. Both actions align with the NIST SP 800-61 containment strategy of stopping the spread and impact of an incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Isolate the workstation from the network.

    Why this is correct

    Isolating the workstation from the network, by unplugging the cable or disabling the Wi-Fi adapter, immediately severs all communication paths to the unknown host. This stops malicious traffic, prevents lateral movement to other systems, and preserves both memory and disk artifacts in their current state for forensic acquisition, making it the preferred first containment step in incident response.

  • Block the malicious IP or domain at the firewall or proxy.

    Why this is correct

    Blocking the malicious IP or domain at the firewall or proxy provides a targeted, reversible containment method that cuts command-and-control traffic while leaving the workstation powered on and observable. This allows incident responders to continue monitoring the host's behavior and collect memory and logs without the attacker's outbound influence, though it does not stop local process execution.

  • Reimage the workstation immediately before collecting evidence.

    Why it's wrong here

    Reimaging the workstation before collecting evidence destroys volatile data in memory, the malware binary itself, and key artifacts such as registry entries, prefetch files, and event logs. This violates the fundamental forensic principle of preserving original evidence, and without a full disk image and memory dump, the investigation cannot determine the infection vector, scope of compromise, or associated indicators of compromise.

  • Tell the user to keep working until tomorrow.

    Why it's wrong here

    Telling the user to keep working until tomorrow leaves the malware active, allowing continued command-and-control communication, data exfiltration, or further propagation across the network. This abdicates the incident response duty of containment and also risks the user inadvertently deleting or altering evidence while systems remain compromised, potentially expanding the damage and making eradication more difficult.

  • Delete recent logs to reduce noise.

    Why it's wrong here

    Deleting recent logs to reduce noise removes the exact artifacts needed to reconstruct the attack timeline: network connections, process executions, file modifications, and authentication events. Logs are primary sources of evidence for identifying the unknown host, the infection vector, and the actions taken by the malware, and destroying them severely hampers the investigation and any later legal or remediation efforts.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.