Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

The SOC has contained a mailbox compromise by resetting the password and revoking active sessions. Investigation shows the attacker created an automatic forwarding rule and added an OAuth consent grant. What should happen next to eradicate the threat?

⚠ Common exam trap

Test-takers frequently assume a password reset and session revocation fully remediate the compromise, overlooking the fact that OAuth consent grants and mailbox forwarding rules are independent persistence mechanisms that must be explicitly removed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Remove the malicious forwarding rule and review or revoke suspicious OAuth app grants.

The immediate next step after containment is to remove the attacker's persistence mechanisms. The malicious forwarding rule (which exfiltrates emails via SMTP) and the OAuth consent grant (which provides persistent API access) must be removed to fully eradicate the threat. Simply resetting the password and revoking sessions does not remove these backdoors, as OAuth grants persist independently of user credentials.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Notify all employees to be more careful with email before taking any technical steps.

    Why it's wrong here

    Phishing awareness training is a preventive measure that addresses future user susceptibility, but it does nothing to disrupt an ongoing intrusion. The attacker has already established persistence through mechanisms such as mailbox forwarding rules, OAuth application consent, or delegated access, and these remain active even if users become more cautious. Technical containment and eradication must happen first to remove the adversary's foothold.

  • Delete the mailbox and create a new account for the user immediately.

    Why it's wrong here

    Deleting the mailbox and recreating the account is unnecessarily destructive and can result in permanent loss of business-critical email while destroying forensic evidence needed for the incident investigation. It also fails to address the root cause, because the attacker's credentials or OAuth refresh tokens may still be valid for other resources, and a new mailbox could be recompromised through the same vector. Recreating an account should be a last resort, not a routine eradication step.

  • Remove the malicious forwarding rule and review or revoke suspicious OAuth app grants.

    Why this is correct

    Eradication means removing the adversary's persistence mechanisms and closing the foothold they created. In a mailbox compromise, forwarding rules and unauthorized OAuth consents are common persistence methods. Removing those artifacts, then confirming no other malicious rules or delegated access remain, is the correct next step before returning the account to normal use and monitoring for recurrence.

  • Restore the user's messages from backup and reopen access without further review.

    Why it's wrong here

    Restoring messages from backup only replaces the data content and does not remove the attacker's persistence mechanisms, such as hidden inbox rules, mailbox delegation, or OAuth grants that allow continued access via the Graph API. If the account is reopened immediately, the attacker can still read, forward, or delete mail using the same compromised tokens or rules. Backup restoration is appropriate after eradication to recover missing data, not as a substitute for removing the attacker's access.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.