CompTIA Security+ SY0-701 (V7) Practice Question

A security analyst, reviewing alerts from an Endpoint Detection and Response (EDR) system, notices suspicious command-line activity on a user's workstation indicative of a malware infection. The analyst needs to contain the threat while preserving evidence for a forensic investigation. What is the BEST immediate action for the analyst to take?

  • Run a full antivirus scan on the workstation while it remains connected to the network.

  • Immediately power off the workstation to stop the malware's execution.

  • Disconnect the workstation from the network and immediately re-image it from a known-good backup.

  • Isolate the workstation from the network but leave it powered on.

CompTIA Security+ SY0-701 (V7)
Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA Security+ Voucher with Retake
v7 / SY0-701
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot