nerdexam
CompTIA

SY0-701 · Question #946

An EDR solution recognizes that a specific workstation has outbound traffic to a malicious IP. Which of the following would be the best action to take to contain the threat?

The correct answer is B. Isolate the workstation as part of immediate response. Isolating the workstation immediately stops communication with the malicious IP and prevents further spread or data exfiltration, making it the most effective containment action.

Submitted by jakub_pl· Mar 6, 2026Security Operations

Question

An EDR solution recognizes that a specific workstation has outbound traffic to a malicious IP. Which of the following would be the best action to take to contain the threat?

Options

  • AChange the passwords for all users accessing that workstation.
  • BIsolate the workstation as part of immediate response.
  • CPatch the workstation because it is likely vulnerable.
  • DReview the hardening and policies affecting that workstation.

How the community answered

(49 responses)
  • A
    4% (2)
  • B
    86% (42)
  • C
    8% (4)
  • D
    2% (1)

Explanation

Isolating the workstation immediately stops communication with the malicious IP and prevents further spread or data exfiltration, making it the most effective containment action.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice