nerdexam
CompTIA

SY0-501 · Question #483

A computer emergency response team is called at midnight to investigate a case in which a mail server was restarted. After an initial investigation, it was discovered that email is being exfiltrated…

The correct answer is A. Identify the source of the active connection. After discovering email exfiltration through an active connection, the immediate next step in incident response is to identify the source to understand the attack's scope and nature.

Submitted by alyssa_d· Mar 4, 2026Security operations

Question

A computer emergency response team is called at midnight to investigate a case in which a mail server was restarted. After an initial investigation, it was discovered that email is being exfiltrated through an active connection. Which of the following is the NEXT step the team should take?

Options

  • AIdentify the source of the active connection
  • BPerform eradication of active connection and recover
  • CPerformance containment procedure by disconnecting the server
  • DFormat the server and restore its initial configuration

How the community answered

(22 responses)
  • A
    82% (18)
  • B
    5% (1)
  • C
    5% (1)
  • D
    9% (2)

Why each option

After discovering email exfiltration through an active connection, the immediate next step in incident response is to identify the source to understand the attack's scope and nature.

AIdentify the source of the active connectionCorrect

In the incident response lifecycle, after initial discovery, the identification phase involves gathering information about the incident, including the source and method of attack. Identifying the source of the active connection is crucial for understanding how the exfiltration is occurring and informing subsequent containment strategies, ensuring effective remediation.

BPerform eradication of active connection and recover

Eradication and recovery are later stages of incident response, performed after identification and containment; attempting them without full understanding can be ineffective or incomplete.

CPerformance containment procedure by disconnecting the server

While containment is critical, disconnecting the server immediately without first identifying the connection's source could destroy volatile evidence or prevent full understanding of the attack, hindering comprehensive remediation.

DFormat the server and restore its initial configuration

Formatting the server is a drastic measure typically reserved for recovery, which would destroy all forensic evidence vital for investigation and preventing future incidents.

Concept tested: Incident Response Lifecycle - Identification Phase

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#incident response#email exfiltration#forensic analysis#containment

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice