Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIASecurity+

Domain 4Objective 8

Incident Response SY0-701 Practice Questions (Page 1)

Part of the Security operations domain, which accounts for 28% of the SY0-701 exam. CompTIA does not publish an official question count, but from its 90-minute exam (~35–60 total, ~10–17 in this domain), expect 1–2 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)

26questions here
6free pages
6concepts
28%of the exam

Questions 1–5

  1. 1foundation · easy

    A security analyst is documenting the actions taken to contain an active malware infection. According to common incident response frameworks, which phase of the incident response process does containment fall under?

    Select an answer first
  2. 2application · medium

    During an investigation of a suspected data breach, the incident response team needs to collect evidence from a compromised server. The server is still running and is critical to business operations. The team must preserve evidence in a way that is admissible in court. Which action is the MOST appropriate FIRST step?

    Select an answer first
  3. 3foundation · easy

    An organization is establishing a formal process for handling security incidents. Which activity is typically performed during the preparation phase of the incident response process?

    Select an answer first
  4. 4application · medium

    A security operations center (SOC) analyst notices a pattern of small, encrypted data transfers from a database server to an external IP address during off-peak hours. The transfers have been occurring for several weeks and have not triggered any alerts. The analyst suspects data exfiltration. Which action should the analyst take FIRST?

    Select an answer first
  5. 5expert · hard

    A company experienced a data breach where customer data was exfiltrated. The investigation found that the attacker gained access through a phishing email that compromised a user's credentials. The user had multi-factor authentication (MFA) enabled, but the attacker used a phishing kit that intercepted the MFA token in real-time. The company has since reset the user's credentials and blocked the attacker's IP. Management wants to prevent a recurrence. Which action is the MOST direct application of root cause analysis?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “SY0-701” is a trademark of its owner, used for identification only.