Courseiva
hardMultiple ChoiceObjective-mapped

220-1202 Practice Question: A technician is investigating a computer that has…

A technician is investigating a computer that has been sending spam emails from the user's account without their knowledge. The user has not installed any new software recently. The technician finds a process running that matches a known botnet client. Which two steps should the technician take first to mitigate the threat?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disconnect the computer from the network and terminate the malicious process.

The immediate priority is to disconnect the computer from the network to stop the botnet communication and prevent further spam. Then, the technician should identify and terminate the malicious process. Scanning without disconnecting may allow continued data exfiltration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disconnect the computer from the network and terminate the malicious process.

    Why this is correct

    This is the correct initial response to an active botnet infection. Disconnecting the computer from the network immediately severs its communication with the botnet's command-and-control (C2) server, preventing it from receiving further instructions or participating in malicious activities like sending spam. Concurrently, terminating the malicious process halts the immediate execution of the malware on the system, mitigating ongoing resource consumption and preventing further damage. This two-pronged approach prioritizes immediate containment and neutralization of the active threat.

  • Run a full antivirus scan and then update the firewall rules.

    Why it's wrong here

    Initiating a full antivirus scan without first isolating the infected machine from the network is a significant oversight. While a scan is essential for remediation, an active botnet could continue to receive new commands, exfiltrate sensitive data, or even propagate to other network devices during the scanning process. Updating firewall rules is a crucial preventative measure for future threats, but it will not stop an already established and active botnet connection that has likely bypassed existing security controls. The immediate priority must be containment to prevent further harm.

  • Change the user's email password and run a malware scan.

    Why it's wrong here

    Changing the user's email password, while a critical step in post-incident recovery to secure compromised accounts, does not address the immediate threat of an active botnet process on the infected computer. The botnet is likely operating at a system level, using the computer's resources to send spam directly, independent of the email account's password. Running a malware scan is necessary for eradication, but without prior network disconnection, the botnet could continue its malicious activities or receive updates from its command-and-control server, potentially hindering the scan's effectiveness or allowing reinfection. Containment must precede remediation efforts.

  • Reboot the computer into Safe Mode and then run a scan.

    Why it's wrong here

    Rebooting the computer into Safe Mode can be a valuable step for malware removal, as it loads only essential system services and drivers, often preventing malware from fully loading or executing. However, it is not the immediate first step for an active botnet. The primary concern is to stop the ongoing malicious network activity, such as sending spam or receiving C2 commands. Rebooting, even into Safe Mode, takes time during which the botnet could continue to operate if the network connection is still active, potentially causing further damage or spreading. Network isolation must precede any reboot or scanning to ensure immediate containment.

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.