What Should a SOC Analyst Do First After Discovering Exposed Credentials?

A SOC analyst establishes a remote control session on an end user’s machine and discovers the following in a file: gmail.com[ENT][email protected][ENT]NoOneCanGuessThis123! [ENT]Hello Susan, it was great to see you the other day! Let’s plan a followup[BACKSPACE]follow-up meeting soon. Here is the link to register. [RTN][CTRL]c [CTRL]v [RTN]after[BACKSPACE]After you register give me a call on my cellphone. Which of the following actions should the SOC analyst perform first?

  1. Advise the user to change passwords. Source Reference Answer
  2. Reimage the end user’s machine.
  3. Check the policy on personal email at work.
  4. Check host firewall logs.

Community Votes

A
64%
B
36%

64% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question traps candidates into selecting system eradication over account recovery, overlooking that active credential theft requires immediate rotation to prevent exploitation.

This SY0-701 question evaluates immediate incident response priorities when plaintext credentials are discovered on a compromised host. The community consensus strongly supports advising the user to change passwords first to halt unauthorized access before initiating system remediation.

Candidates frequently choose reimaging the machine first, arguing that a keylogger will capture newly typed passwords. This overlooks the fact that delaying password changes allows attackers to immediately use the captured credentials across multiple platforms.

Community Discussion (8 comments)

nocwyn 👍 1 Selected: B
If they have a keylogger, you cant be sure what type of malware or if its just 1. You reimage the machine.
cab08df 👍 1 Selected: A
A. Only because the user could use a different device to change their password that is currently exposed.
fc040c7 👍 1 Selected: A
Keylogger present. First priority should be to tell them to change their password. Afterwards, take care of the keylogger issue.
AriGarcia 👍 1 Selected: A
Although the SOC analyst should reimage the computer to get rid of the keyloger. The first thing to do is have the user change passwordl.
Bunaventi 👍 1 Selected: A
I think a) advise to change pw is better than B) reimage the end user because changing the exposed password immediately prevents unauthorized access, whereas reimaging the machine is a more drastic step that comes later after confirming a compromise.
b422ce6 👍 2 Selected: B
Changing the password on an infected machine would do no good, as the password could still be leaked with a keylogger, etc. Reimaging the system FIRST would be best in this scenario.
1eccfc0 👍 3 Selected: A
The correct answer is A. Advise the user to change passwords. Here's why: The file contains sensitive information, including an email address and a password ("NoOneCanGuessThis123!"), along with a suspicious message that includes commands like "[CTRL]c" and "[CTRL]v" (which may indicate attempts to copy/paste content, possibly in a malicious context). The immediate concern is the password being exposed. Given that the password appears in plaintext, the first action should be to advise the user to change their password—especially since it may be associated with a critical account (e.g., Gmail) that could be used for further attacks. It’s also important to ensure that the user is aware of the potential compromise and that the password isn't being used elsewhere.
Clau95 👍 1 Selected: B
Answer B - To ensure the integrity of the system and prevent any further compromise, the first priority should be to reimage the end user's machine. Reimaging will remove any potential malware or unauthorized software that may be affecting the system.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Incident Response Priority

When a SOC analyst detects plaintext credentials alongside keylogging artifacts (such as [ENT], [CTRL]c, and [CTRL]v sequences), the immediate threat is active credential compromise. According to the NIST incident response lifecycle and CompTIA Security+ best practices, the highest priority is containment and recovery. Advising the user to change their passwords immediately invalidates the stolen credentials, stopping potential lateral movement and unauthorized access.

Why Reimaging Is Not the First Step

Reimaging the endpoint (Option B) is a vital eradication and recovery measure, but it is not the first action. While some community members correctly note that a persistent keylogger could capture new logins, CompTIA prioritizes neutralizing the active threat vector first. Credential rotation should be performed using a known-clean device, followed by isolation and reimaging. As highlighted by top-voted candidates, securing the account prevents further damage while the technical cleanup proceeds.

Evaluating Distractors

Checking workplace email policies (Option C) addresses compliance rather than security, making it irrelevant to immediate threat mitigation. Reviewing host firewall logs (Option D) may provide forensic context but does nothing to stop active exploitation of the stolen password. The correct sequence is always: contain/secure accounts -> isolate host -> eradicate malware -> recover system.

Community Consensus

The split between Options A and B reflects a common real-world debate, but exam logic strictly follows the "first actionable step" rule. Community experts consistently emphasize that once credentials are exposed, immediate rotation outweighs forensic preservation or system wiping in priority.

Official Reference

Exam Strategy

When tackling incident response questions, always identify the exact phase of the IR lifecycle being tested. If credentials or sensitive data are actively exposed, prioritize account recovery and containment before moving to eradication or system restoration steps. Remember that CompTIA expects you to choose the action that stops the immediate breach, not the one that cleans up the root cause.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide