220-1102 Operational Procedures Practice Question
A help desk technician receives a call from a user who claims that their computer is infected with a virus. The user has already run an antivirus scan and deleted some files. The technician follows the incident response plan. What should the technician do FIRST?
⚠ Common exam trap
A common mix-up: candidates confuse the incident response order and choose 'Document the incident' (Option A) first, but CompTIA emphasizes that preservation of evidence takes priority over documentation in the initial response phase.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preserve the current state of the system
The correct first step in any incident response is to preserve the current state of the system (Option C). This ensures that volatile data (e.g., running processes, network connections, memory contents) and the existing file system are captured before any further changes occur. Since the user has already run an antivirus scan and deleted files, the technician must immediately create a forensic image or memory dump to prevent loss of critical evidence and to maintain the integrity of the incident scene.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Document the incident
Why it's wrong here
Documenting the incident is a necessary part of incident response, but it should not be the first action. In forensic procedure, you must preserve volatile evidence (memory, running processes) and create a forensic image before you document details, since documentation can be performed later without altering data. Acting too slowly to document risks losing the evidence that your documentation should describe, so preservation takes precedence.
- ✗
Identify the malware type
Why it's wrong here
Identifying the malware type is a goal of the analysis phase, which comes only after you have preserved the current state of the system. Running antimalware scans or reverse engineering tools against a live system modifies files, timestamps, and memory, potentially corrupting evidence. To identify malware accurately and legally, you must first capture a memory dump and a bit-for-bit disk image, then analyze those images in a controlled environment.
- ✓
Preserve the current state of the system
Why this is correct
Preserving the current state of the system is the correct first step because volatile data—such as RAM contents, open network connections, and running processes—will be lost the moment the system is rebooted or powered off. A properly preserved forensic image and memory dump ensure that all potential evidence is intact for later analysis and maintains the chain of custody. This is the only option that protects the integrity of the investigation before any alterations occur.
- ✗
Reinstall the operating system
Why it's wrong here
Reinstalling the operating system is a remediation and recovery action that must wait until after evidence preservation and analysis have been completed. Wiping and reinstalling destroys all artifacts on the disk and clears memory, making it impossible to determine what malware was present, how it entered, or what data was exfiltrated. It also violates forensic best practices because it modifies the system state before evidence has been collected.
Go deeper
Related to this question
Learn chapter
User Account Control (UAC)
Key term
Antivirus
Antivirus is software that detects, prevents, and removes malicious software (malware) from a computer or network.
Key term
Image
An image is a complete snapshot of a system's operating system, applications, and settings, used to deploy or restore computing environments quickly.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.