220-1202 Operational Procedures Practice Question
A technician is troubleshooting a Windows 10 workstation that is running very slowly. The technician suspects a malware infection. Which of the following should the technician do FIRST according to best practices for malware removal?
⚠ Common exam trap
The trap here is jumping straight to scanning or restoring, but containment must come first to prevent the malware from spreading.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Quarantine the system by disconnecting it from the network.
The first step in malware removal is to quarantine the infected system by disconnecting it from the network. This prevents the malware from spreading to other systems and stops any remote communication. Only after isolation should the technician proceed with scanning, removal, and recovery. Educating the user and restoring from backup are subsequent steps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Quarantine the system by disconnecting it from the network.
Why this is correct
Disconnecting the system from the network prevents the malware from spreading or communicating with command-and-control servers. This is the first step in the malware removal process to contain the infection. It also preserves evidence and prevents further damage while the technician investigates. Quarantining is a critical initial action before attempting removal.
- ✗
Restore the system from a known good backup.
Why it's wrong here
Restoring from backup might be necessary if the malware cannot be removed, but it is not the first step. You should first attempt to quarantine and remove the malware. Restoring prematurely could reintroduce the malware if the backup is also infected or if the root cause is not addressed. Backup restoration is typically a later step in the remediation process.
- ✗
Educate the end user about safe browsing habits.
Why it's wrong here
User education is valuable for prevention, but it is not the first step during an active infection. The priority is to contain and remove the malware. Educating the user can happen later as part of post-incident follow-up. Focusing on education first leaves the system vulnerable and the malware active.
- ✗
Run a full antivirus scan immediately.
Why it's wrong here
Running a full scan is important, but it should be done after quarantining the system. If the system remains connected, the malware could spread or the scan might be ineffective if the malware disables the antivirus. The first step is to isolate the system to prevent propagation, then proceed with scanning and removal.
Go deeper
Related to this question
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.