What Should a SOC Analyst Do First After Discovering Exposed Credentials?
A SOC analyst establishes a remote control session on an end user’s machine and discovers the following in a file: gmail.com[ENT][email protected][ENT]NoOneCanGuessThis123! [ENT]Hello Susan, it was great to see you the other day! Let’s plan a followup[BACKSPACE]follow-up meeting soon. Here is the link to register. [RTN][CTRL]c [CTRL]v [RTN]after[BACKSPACE]After you register give me a call on my cellphone. Which of the following actions should the SOC analyst perform first?
Community Votes
64% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question traps candidates into selecting system eradication over account recovery, overlooking that active credential theft requires immediate rotation to prevent exploitation.
This SY0-701 question evaluates immediate incident response priorities when plaintext credentials are discovered on a compromised host. The community consensus strongly supports advising the user to change passwords first to halt unauthorized access before initiating system remediation.
Candidates frequently choose reimaging the machine first, arguing that a keylogger will capture newly typed passwords. This overlooks the fact that delaying password changes allows attackers to immediately use the captured credentials across multiple platforms.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Incident Response Priority
When a SOC analyst detects plaintext credentials alongside keylogging artifacts (such as [ENT], [CTRL]c, and [CTRL]v sequences), the immediate threat is active credential compromise. According to the NIST incident response lifecycle and CompTIA Security+ best practices, the highest priority is containment and recovery. Advising the user to change their passwords immediately invalidates the stolen credentials, stopping potential lateral movement and unauthorized access.Why Reimaging Is Not the First Step
Reimaging the endpoint (Option B) is a vital eradication and recovery measure, but it is not the first action. While some community members correctly note that a persistent keylogger could capture new logins, CompTIA prioritizes neutralizing the active threat vector first. Credential rotation should be performed using a known-clean device, followed by isolation and reimaging. As highlighted by top-voted candidates, securing the account prevents further damage while the technical cleanup proceeds.Evaluating Distractors
Checking workplace email policies (Option C) addresses compliance rather than security, making it irrelevant to immediate threat mitigation. Reviewing host firewall logs (Option D) may provide forensic context but does nothing to stop active exploitation of the stolen password. The correct sequence is always: contain/secure accounts -> isolate host -> eradicate malware -> recover system.Community Consensus
The split between Options A and B reflects a common real-world debate, but exam logic strictly follows the "first actionable step" rule. Community experts consistently emphasize that once credentials are exposed, immediate rotation outweighs forensic preservation or system wiping in priority.Official Reference
- NIST Special Publication 800-61 Rev. 2: Computer Security Incident Handling Guide
- CompTIA Security+ SY0-701 Official Study Guide: Domain 4.0 - Incident Response
- https://www.comptia.org/training-resources/security-sy0-701
Exam Strategy
When tackling incident response questions, always identify the exact phase of the IR lifecycle being tested. If credentials or sensitive data are actively exposed, prioritize account recovery and containment before moving to eradication or system restoration steps. Remember that CompTIA expects you to choose the action that stops the immediate breach, not the one that cleans up the root cause.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →