SY0-701 exam dumps

SY0-701 practice question 386 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 386

Single answerProcess: Preparation , Detection , Analysis , Containment , Eradication , Recovery , Lessons learned , Training

A company’s security team detects ransomware activity on a file server after several users report that shared documents are suddenly inaccessible and renamed with a new extension. The incident response lead confirms the affected server is actively encrypting files, but no evidence suggests the malware has spread beyond that host. The company has current offline backups and a documented incident response plan. Which action should the team take NEXT according to the incident response process?

  1. A

    Restore the server from the latest offline backup to minimize downtime

  2. B

    Disconnect the affected server from the network to stop further encryption and limit spread

  3. C

    Conduct a lessons-learned meeting to identify gaps in ransomware awareness training

  4. D

    Reimage the affected server and return it to production after validating patches

Show answer and explanation

Correct answer: B

Explanation

The correct answer is to disconnect the affected server from the network because the incident response process generally follows preparation, detection, analysis, containment, eradication, recovery, and lessons learned, with training supporting readiness and improvement. In this scenario, detection and analysis have already occurred: the team knows ransomware is actively encrypting files on one server. The most appropriate next step is containment to limit business impact and prevent propagation. After containment, the team can preserve evidence as needed, eradicate the malware through reimaging or other approved methods, recover from known-good offline backups, validate normal operations, and then conduct lessons learned and update training. This sequence aligns with common incident handling guidance such as NIST SP 800-61 Computer Security Incident Handling Guide, which emphasizes containing an incident before eradication and recovery.

  • A. Incorrect.

    This is incorrect because restoring from backup is part of recovery, which occurs after the immediate threat has been contained and eradicated. If the server is restored before isolation, the ransomware could continue encrypting data or re-infect restored systems. Candidates may choose this option because backups are available and downtime is a concern, but the incident response process prioritizes containment once active malicious activity is confirmed.

  • B. Correct.

    This is correct because the scenario shows the team has already performed detection and initial analysis: they know ransomware is actively encrypting files on a specific server and there is no current evidence of spread. The next step is containment, which commonly includes isolating the affected host from the network to stop ongoing damage and reduce the chance of lateral movement. This is a practical and standard immediate response to active ransomware on a known host.

  • C. Incorrect.

    This is incorrect because lessons learned and training occur after the incident has been contained, eradicated, and recovery activities are complete. Although user awareness and process improvements are important, they are not the next action while the system is still actively encrypting files. This distractor reflects a common mistake of jumping to process improvement before stabilizing the incident.

  • D. Incorrect.

    This is incorrect because reimaging is an eradication activity, not the next step when ransomware is still active. The team should first contain the incident to prevent additional encryption or spread. Reimaging before containment may also destroy valuable forensic evidence and does not address the immediate need to stop the active attack.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam