nerdexam
CompTIA

SY0-501 · Question #459

A security analyst is investigating a potential reach. Upon gathering, documenting, and securing the evidence, which of the following actions is the NEXT step to minimize the business impact?

Sign in or unlock SY0-501 to reveal the answer and full explanation for question #459. The question stem and answer options stay visible for context.

Submitted by amina.ke· Mar 4, 2026Security operations

Question

A security analyst is investigating a potential reach. Upon gathering, documenting, and securing the evidence, which of the following actions is the NEXT step to minimize the business impact?

Options

  • ALaunch an investigation to identify the attacking host
  • BInitiate the incident response plan
  • CReview lessons learned captured in the process
  • DRemove malware and restore the system to normal operation

Unlock SY0-501 to see the answer

You've previewed enough free SY0-501 questions. Unlock SY0-501 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#incident response#evidence handling#malware removal#business continuity
Full SY0-501 Practice