nerdexam
CompTIA

SY0-501 · Question #483

A computer emergency response team is called at midnight to investigate a case in which a mail server was restarted. After an initial investigation, it was discovered that email is being exfiltrated t

Sign in or unlock SY0-501 to reveal the answer and full explanation for question #483. The question stem and answer options stay visible for context.

Submitted by alyssa_d· Mar 4, 2026Security operations

Question

A computer emergency response team is called at midnight to investigate a case in which a mail server was restarted. After an initial investigation, it was discovered that email is being exfiltrated through an active connection. Which of the following is the NEXT step the team should take?

Options

  • AIdentify the source of the active connection
  • BPerform eradication of active connection and recover
  • CPerformance containment procedure by disconnecting the server
  • DFormat the server and restore its initial configuration

Unlock SY0-501 to see the answer

You've previewed enough free SY0-501 questions. Unlock SY0-501 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#incident response#email exfiltration#forensic analysis#containment
Full SY0-501 Practice