Courseiva
Operational Procedures →hardMultiple Choice

220-1102 Operational Procedures Practice Question

A help desk technician receives a call from a user reporting that their workstation is infected with ransomware. The technician has isolated the system from the network by unplugging the Ethernet cable. According to incident response best practices, what should the technician do NEXT?

⚠ Common exam trap

The trap here is that candidates often jump to remediation (reimaging or scanning) immediately after containment, forgetting that incident response requires formal documentation and escalation before any eradication or recovery steps are taken.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the incident and report it to the appropriate authority (e.g., security team, management).

After isolating the infected system from the network, the next step in incident response best practices is to document the incident and report it to the appropriate authority (e.g., security team, management). This aligns with the NIST SP 800-61 incident response framework, which prioritizes containment, documentation, and escalation before any remediation actions like reimaging or scanning. Reporting ensures that the incident is formally logged, the chain of custody is preserved, and the response team can coordinate further investigation or legal actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reimage the workstation immediately.

    Why it's wrong here

    Reimaging the workstation would erase the ransomware binary, logs, and other digital artifacts before they can be collected, breaking the chain of custody and hampering forensic analysis. Even if the machine will eventually need to be rebuilt, the incident must first be reported and documented so the security team can capture evidence and determine the full scope of the compromise. Remediation actions like reimaging belong to the later eradication phase of incident response, not the initial response.

  • ✗

    Scan the system with an antivirus to remove the ransomware.

    Why it's wrong here

    Running an antivirus scan is reactive and premature because it can modify or quarantine the exact files needed for incident analysis, destroying evidence like malware variants and execution timestamps. Ransomware often cannot be removed by antivirus software alone; encrypted files require restoration from clean backups, which is a decision that belongs to the security team. The help desk technician's responsibility is to contain the immediate threat and report the incident, not to run unapproved remediation tools that could contaminate the forensic trail.

  • ✓

    Document the incident and report it to the appropriate authority (e.g., security team, management).

    Why this is correct

    Documenting the incident and reporting it to the security team or management is the mandatory first step per incident response frameworks, ensuring proper procedures are followed and legal/compliance obligations are met. This documentation should include the time of discovery, user actions, error messages, and any steps already taken, allowing the security team to escalate appropriately and preserve evidence. Only after reporting can containment, eradication, and recovery be coordinated by the designated incident response team.

  • ✗

    Pay the ransom to retrieve the data.

    Why it's wrong here

    Paying the ransom provides no guarantee that the decryption key will be delivered, and many attackers take the money and vanish, leaving the data permanently irretrievable. It also funds further cybercrime and may violate federal sanctions or data privacy laws, making it an executive-level decision rather than a help desk call. The correct course is to report the incident immediately so the security team can evaluate options such as backup restoration or known decryption tools—never negotiate with attackers independently.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.