nerdexam
CompTIA

SY0-501 · Question #459

A security analyst is investigating a potential reach. Upon gathering, documenting, and securing the evidence, which of the following actions is the NEXT step to minimize the business impact?

The correct answer is D. Remove malware and restore the system to normal operation. After evidence is gathered and secured during a breach investigation, the next priority is containment and recovery to minimize business impact by removing malware and restoring systems to normal operation.

Submitted by amina.ke· Mar 4, 2026Security operations

Question

A security analyst is investigating a potential reach. Upon gathering, documenting, and securing the evidence, which of the following actions is the NEXT step to minimize the business impact?

Options

  • ALaunch an investigation to identify the attacking host
  • BInitiate the incident response plan
  • CReview lessons learned captured in the process
  • DRemove malware and restore the system to normal operation

How the community answered

(21 responses)
  • A
    5% (1)
  • C
    10% (2)
  • D
    86% (18)

Why each option

After evidence is gathered and secured during a breach investigation, the next priority is containment and recovery to minimize business impact by removing malware and restoring systems to normal operation.

ALaunch an investigation to identify the attacking host

Launching an investigation to identify the attacking host is a forensic/attribution task that occurs during analysis, not after evidence collection when business continuity is the priority.

BInitiate the incident response plan

Initiating the incident response plan would have already occurred before evidence gathering began, as evidence collection is itself a step within the incident response process.

CReview lessons learned captured in the process

Reviewing lessons learned is the final post-incident phase that takes place after the incident has been fully resolved and systems have been restored, not immediately after evidence collection.

DRemove malware and restore the system to normal operationCorrect

Once evidence has been gathered, documented, and secured, the immediate next step to minimize business impact is remediation - removing malware and restoring affected systems to normal operation. This aligns with the incident response lifecycle where containment and eradication follow evidence collection, directly reducing downtime and limiting further damage to the organization.

Concept tested: Incident response lifecycle order and business impact minimization

Source: https://www.nist.gov/publications/computer-security-incident-handling-guide

Topics

#incident response#evidence handling#malware removal#business continuity

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice