Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Incident Response Phases Practice Question

A user reports that their workstation is infected with ransomware. The technician isolates the computer from the network by disconnecting the network cable. What should the technician do NEXT according to incident response procedures?

⚠ Common exam trap

Many candidates confuse the order of incident response steps, thinking forensic collection (Option D) or antivirus scanning (Option A) should come immediately after isolation, when in fact eradication and recovery (wipe and restore) take precedence to stop the spread and restore operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Wipe the hard drive and restore from a known good backup

After isolating the infected workstation by disconnecting the network cable, the next step in incident response is to contain the threat and begin recovery. Wiping the hard drive and restoring from a known good backup (Option C) follows the NIST SP 800-61 recovery phase, ensuring the ransomware is completely removed and the system is returned to a clean state. Running a full antivirus scan (Option A) is unreliable because ransomware often disables or evades antivirus software, and scanning could trigger further encryption or damage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a full antivirus scan on the workstation

    Why it's wrong here

    Running an antivirus scan on a ransomware-infected workstation is an unreliable eradication method because modern ransomware can disable or evade endpoint protection and the primary damage—file encryption—is often already complete. AV detection signatures may not yet cover the specific ransomware variant, and even if files are quarantined, encrypted user data remains inaccessible. The safer incident-response approach is to treat the system as compromised, wipe it, and restore from a verified clean backup rather than spending time on a scan that does not guarantee recovery.

  • ✗

    Notify law enforcement and the company's legal department

    Why it's wrong here

    While notifying law enforcement and legal counsel may eventually be necessary for compliance, insurance, or criminal investigation, it does nothing to stop the spread of ransomware or recover encrypted files. The immediate technical priority is containment—isolating the workstation from the network—and beginning eradication/recovery steps. Legal notification is a parallel process that can happen while technicians wipe and restore, but it is not the next operational action to resolve the infection.

  • ✓

    Wipe the hard drive and restore from a known good backup

    Why this is correct

    Wiping the hard drive and restoring from a known good backup is the definitive remediation because ransomware can persist through normal deletions or even hide in boot sectors, and you cannot trust that a scan removed every component. A full wipe eliminates all malicious files and any changes to the operating system, while restoring user data from a clean offline backup brings operations back without paying the ransom. Before restoring, verify the backup predates the initial infection and is free of the ransomware payload, and ensure the restored system is patched to prevent re-infection.

  • ✗

    Collect forensic data for analysis

    Why it's wrong here

    Forensic data collection is often a deliberate pre-eradication step because wiping the drive destroys evidential artifacts and complicates attribution or legal prosecution, but it is not always the immediate priority in every incident response playbook. Many organizations prioritize containment and rapid recovery to minimize business disruption, especially when clean backups exist, and thus skip or defer forensics. If legal action is anticipated, preserve memory and disk images before wiping, but this decision is separate from the core remediation objective and may be outweighed by recovery urgency.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.