CompTIA Security+ SY0-701 Practice Question

During an incident response, an organization has identified an infected workstation that is part of a botnet and is communicating with external command and control servers. What is the BEST immediate action to contain this threat?

  • Capture network traffic to analyze the communication with the command and control servers

  • Change access controls on the infected workstation

  • Perform a vulnerability scan to identify the infected workstation

  • Isolate the infected workstation from the network

CompTIA Security+ SY0-701
Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot