Courseiva
Threats, Vulnerabilities, and MitigationseasyMultiple ChoiceObjective-mapped

SY0-701 Threats, Vulnerabilities, and Mitigations Practice Question

A user reports that their laptop is showing frequent pop-up ads, the browser homepage keeps changing, and the system has become noticeably slower. What is the most likely immediate containment action?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disconnect the laptop from the network and begin endpoint isolation

The best immediate action is to isolate the laptop from the network. The symptoms suggest malicious or unwanted software may be communicating with outside servers or affecting the browser. Isolation limits further damage, prevents possible spread, and gives responders time to inspect the system safely. This is a standard first containment step when a workstation appears compromised but is still active. Why others are wrong: Keeping the laptop online risks continued malicious activity. Reimaging too early can destroy evidence needed for root-cause analysis. Simply reinstalling the browser may remove a symptom, but it does not address the possibility of a broader endpoint compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Keep the laptop online so security tools can continue collecting data

    Why it's wrong here

    Keeping a potentially infected laptop online allows the suspected malware to continue command-and-control communications, potentially exfiltrating sensitive data or propagating to adjacent systems. While collecting live telemetry can be valuable, the immediate risk to the network outweighs that benefit. The safer approach is to physically disconnect or logically isolate the endpoint, then capture forensic images or memory dumps for analysis.

  • Disconnect the laptop from the network and begin endpoint isolation

    Why this is correct

    Disconnecting the laptop and isolating the endpoint halts any active malicious network activity, preventing lateral movement and cutting off command-and-control channels before the investigation proceeds. This containment step is the top priority in incident response because it preserves volatile data, such as running processes and network connections, while ensuring the threat cannot spread to other hosts. After isolation, analysts can safely perform triage, evidence preservation, and forensic data collection.

  • Immediately reimage the laptop before preserving any evidence

    Why it's wrong here

    Reimaging the laptop immediately destroys the very evidence needed to identify the infection vector, including malware binaries, registry modifications, and user browsing artifacts. Without preserving a bit-for-bit disk image or conducting memory forensics first, the security team cannot learn how the threat entered or what capabilities it had. Reimaging also does not guarantee the infection originated from this device or that other systems are unaffected, so it may leave the root cause unresolved.

  • Ask the user to uninstall the browser and reinstall it manually

    Why it's wrong here

    Asking the user to uninstall and reinstall the browser may remove the visible homepage hijack, but it leaves any underlying malware—such as a browser extension or a persistent backdoor—untouched and active. The manual uninstall process could also delete browser profile data, erasing potential evidence of malicious activity. Moreover, this action does not contain the threat or stop it from communicating with external servers, so it fails as a first response measure.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.