SEC+ SY0-701 V7 Security operations Runs in your browser · no setup Preview · not independently reviewed

Triage a compromised workstation

Correlate identity and endpoint evidence, then drive the first response actions.

Estimated12 min
DifficultyIntermediate
Points10
Scenario brief

The SOC received an impossible-travel alert for an accounting user. Ten minutes later, the endpoint platform flagged suspicious PowerShell on the user's workstation, WKSTN-22. Assume the incident has been validated and scope is still being determined.

Content record

Preview · not independently reviewed

Mapped to CompTIA SY0-701 objectives · Internal validation 2026-08-12 · Available as preview practice, but a named independent subject-matter expert has not yet verified the question and answer key.

Community review →
4.9Given a scenario, use data sources to support an investigation. 4.8Explain appropriate incident response activities.
Show review record and official sources

Method: Mapped to SY0-701 objectives 4.8 and 4.9; evidence, response sequence, and answer key reviewed.

Current-profile check: 2026-08-12 · Next review due 2026-12-15

01

Inspect the evidence

Use only the information provided to complete the tasks.

Identity events

table
TimeSourceUserResult
08:41198.51.100.42 / USa.chen8 failures
08:44198.51.100.42 / USa.chenSuccess + MFA
08:48203.0.113.77 / NLa.chenSuccess
08:52203.0.113.77 / NLsvc-backupRole added: admin

Endpoint process tree

code
OUTLOOK.EXE
└─ WINWORD.EXE  invoice_aug.docm
   └─ powershell.exe -enc SQBFAFgAIAAoAE4AZQB3AC0A...
      ├─ whoami.exe /all
      └─ rundll32.exe C:\Users\Public\cache.dll,Start
02

Complete the response

Partial credit is available for matching, ordering, and multi-select tasks.

01
multi select

Select the THREE strongest indicators of compromise.

3 pts
Need a hint?

Evaluate each option independently against the scenario evidence instead of treating the list as one decision.

Show another hint

Choose only options that directly satisfy the prompt; being generally true is not enough.

02
ordering

Put the response actions in the best order for this validated incident.

4 pts

Drag the rows or use the arrow buttons to reorder.

  1. 1 Restore the rebuilt endpoint and monitor it
  2. 2 Isolate WKSTN-22 and disable active sessions
  3. 3 Document lessons learned and update detections
  4. 4 Remove persistence and rebuild the affected endpoint
Need a hint?

Identify the prerequisite that must happen first and the verification or documentation that belongs last.

Show another hint

For the middle steps, ask what must already be true before each action can safely happen.

03
matching

Match each action to its primary incident-response purpose.

3 pts
Need a hint?

Start with the row and choice that have the most distinctive purpose, then use that pair to narrow the rest.

Show another hint

For each remaining pair, explain the relationship in one sentence before selecting it.

Ready to check your work?Submit to finish this session and review your feedback. Extra practice is optional.
Persistent progress

Attempt history

Every submission is retained. Starting another attempt never replaces or unlocks the previous one.

No attempts yet

Your first submitted score and detailed answer review will appear here.

Community quality control

Question or answer look wrong?

Proposals and votes help staff prioritize review. They never change the scoring key automatically.

Full review queue
No community corrections yet

Be the first to flag unclear wording, an answer-key issue, or a source that needs another look.

Propose a correction