SY0-701 exam dumps

SY0-701 practice question 132 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 132

Single answerIsolation

A security administrator discovers that a developer's workstation is communicating with a known malicious command-and-control server. The workstation hosts critical source code that must be preserved for forensic review, but the administrator must immediately reduce the risk of lateral movement and further data exfiltration. Which of the following is the BEST action to take first?

  1. A

    Move the workstation to an isolated VLAN or quarantine network with tightly restricted access

  2. B

    Power off the workstation immediately to ensure the malware stops running

  3. C

    Reimage the workstation and restore the developer's files from backup

  4. D

    Disable the user's Active Directory account and leave the workstation connected for monitoring

Show answer and explanation

Correct answer: A

Explanation

This question tests practical use of isolation as a containment control during incident response. When a host is actively communicating with malicious infrastructure, the priority is to contain the threat quickly without unnecessarily destroying evidence. Isolating the endpoint through a quarantine network, isolated VLAN, NAC enforcement, or EDR network containment is a common best practice because it restricts communications while allowing controlled investigation. This approach is consistent with standard incident response phases described by NIST guidance, particularly containment before eradication and recovery. Powering off a system can hinder memory forensics, and reimaging should occur only after evidence is collected and the scope is understood. Disabling the user account may be helpful as a supporting step, but it does not replace host isolation.

  • A. Correct.

    Correct. Isolating or quarantining the affected host is the best immediate step because it contains the incident, limits lateral movement, and reduces ongoing exfiltration while preserving the system for forensic analysis. In practice, organizations often use NAC, EDR containment, or a quarantine VLAN to restrict network communication without fully destroying volatile evidence. This aligns with common incident response guidance to contain first while preserving evidence when possible.

  • B. Incorrect.

    Incorrect. Powering off the workstation may stop malicious activity, but it can also destroy valuable volatile evidence such as running processes, memory-resident malware artifacts, active network connections, and encryption keys. It may be appropriate in some extreme cases, but it is not the best first action when the goal includes preserving the system for forensic review.

  • C. Incorrect.

    Incorrect. Reimaging is a recovery step, not the best first containment action. It would also overwrite evidence needed to understand the scope of compromise, determine what data was accessed, and support any forensic or legal requirements. Before eradication and recovery, the host should be contained and investigated.

  • D. Incorrect.

    Incorrect. Disabling the user's account may reduce abuse of that identity, but it does not isolate the infected endpoint itself. Malware could continue communicating over the network using existing sessions, local system privileges, cached credentials, or other mechanisms. Leaving the workstation connected without containment does not adequately address the immediate threat of lateral movement and exfiltration.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam