hardMultiple ChoiceObjective-mapped
220-1202 Practice Question: A technician is investigating a security incident…
A technician is investigating a security incident where multiple workstations on the same network are showing signs of infection: slow performance, unusual network traffic, and the presence of a file named 'svch0st.exe' in the Startup folder. The technician suspects a worm that spreads through network shares. What is the most effective containment strategy?
⚠ Common exam trap
The 220-1202 exam often tests the distinction between remediation (cleaning the infection) and containment (stopping the spread), and the trap here is that candidates choose a remediation action like scanning or updating definitions instead of the immediate containment step of disabling the propagation vector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable network shares and isolate infected workstations from the network.
Disabling network shares and isolating infected workstations from the network is the most effective containment strategy because the worm spreads through network shares (SMB protocol). By cutting off the propagation vector (network shares) and isolating infected hosts, you prevent the worm from reaching other workstations, even if the malware is still active locally. This aligns with the immediate containment phase of incident response, which prioritizes stopping the spread over remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on all workstations simultaneously.
Why it's wrong here
Initiating full antivirus scans on all workstations simultaneously is premature and potentially counterproductive during an active worm outbreak. While scanning is part of remediation, it consumes significant system resources and network bandwidth, potentially slowing down critical containment efforts. More importantly, it does not prevent the worm from continuing to spread to uninfected or partially scanned machines, as containment (stopping the spread) must be the immediate priority before eradication.
- ✓
Disable network shares and isolate infected workstations from the network.
Why this is correct
Disabling network shares and isolating infected workstations are critical immediate steps for containing a spreading worm. This action directly cuts off common propagation vectors, such as shared folders and network services, preventing the worm from infecting additional machines or escalating its impact. By segmenting the network and quarantining compromised systems, the technician effectively halts the spread, allowing for a more controlled and effective remediation process.
- ✗
Update the antivirus definitions on one workstation and scan it.
Why it's wrong here
Updating antivirus definitions on a single workstation and scanning it, while a necessary step in the remediation phase, does not address the immediate containment of a widespread worm. This action fails to prevent the active propagation of the worm across the network to other vulnerable systems. Without first isolating the threat, the updated workstation could still be reinfected or the worm could continue its spread to other machines that haven't received the updated definitions or scan.
- ✗
Reboot all workstations into Safe Mode with Networking.
Why it's wrong here
Rebooting all workstations into Safe Mode with Networking is an inappropriate initial response to a spreading worm. Although Safe Mode loads a minimal set of drivers and services, the "with Networking" option explicitly enables network connectivity. This means the worm, which propagates via network protocols and shares, could continue its active spread to other systems, negating any potential benefit of Safe Mode for containment. True isolation requires disconnecting from the network entirely.
Go deeper
Related to this question
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.