SY0-701 exam dumps

SY0-701 practice question 168 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 168

Single answerResponsiveness

A company's security operations center detects unusual outbound traffic from a finance workstation at 2:00 p.m. The analyst confirms the host is communicating with a known malicious IP address and may be exfiltrating sensitive data. The incident response plan emphasizes responsiveness and minimizing business impact. Which action should the analyst take FIRST?

  1. A

    Immediately isolate the affected workstation from the network to contain the potential exfiltration

  2. B

    Reimage the workstation to remove any malware before additional files are stolen

  3. C

    Wait until the end of the business day to avoid disrupting the finance department's work

  4. D

    Notify all employees about the incident before taking any technical action

Show answer and explanation

Correct answer: A

Explanation

This question focuses on responsiveness during incident response. In Security+ contexts, responsiveness means taking timely, appropriate action to reduce damage once an incident is identified. When active malicious outbound communication and possible exfiltration are confirmed, containment should occur first. Standard incident response guidance, such as NIST SP 800-61 Computer Security Incident Handling Guide, emphasizes a structured approach: preparation, detection and analysis, containment, eradication, and recovery, followed by post-incident activity. In this case, the most responsive and practical first step is to isolate the host to stop further damage while preserving the ability to investigate. Reimaging too early risks destroying evidence, delaying action increases exposure, and mass communication before containment does not address the immediate threat.

  • A. Correct.

    Correct. In an active incident involving suspected data exfiltration, the first priority is containment. Isolating the workstation quickly limits further communication with the malicious IP and reduces the risk of additional data loss. This reflects strong responsiveness in incident handling while still aligning with standard incident response phases: detection, analysis, containment, eradication, and recovery.

  • B. Incorrect.

    Incorrect. Reimaging is part of eradication and recovery, not the first step in a live incident. If the analyst reimages immediately, important forensic evidence may be lost, and the organization may skip proper containment and analysis. A rapid response should first stop the ongoing harm.

  • C. Incorrect.

    Incorrect. Delaying action conflicts with the principle of responsiveness. Although business disruption is a valid concern, suspected exfiltration presents an immediate security risk that outweighs short-term operational inconvenience. Waiting could allow the attacker to continue stealing data.

  • D. Incorrect.

    Incorrect. Broad employee notification is not the first action in this scenario. Communication is important, but it should follow the organization's incident response procedures and be coordinated appropriately. Immediate technical containment is the priority when active malicious traffic is confirmed.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam