Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A help desk technician receives a call from a user who says their computer is acting strangely. The user reports that they received a pop-up message from 'Windows Security' stating that their computer is infected and to call a number for support. The user called the number and gave the 'technician' remote access. Now the computer is asking for a payment to unlock files. Which type of social engineering attack is this, and what is the BEST immediate action for the technician to take?

⚠ Common exam trap

Candidates often confuse the initial social engineering vector (vishing) with the primary attack type (tech support scam leading to ransomware), or incorrectly assume that running an antivirus scan or changing passwords is sufficient to remediate the ransomware encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

B) This is a tech support scam leading to ransomware; the technician should disconnect the computer from the network and then perform a system restore or restore from backup.

This scenario describes a tech support scam where the attacker tricks the user into granting remote access, then deploys ransomware to encrypt files and demand payment. The best immediate action is to disconnect the computer from the network to prevent the ransomware from spreading laterally, then perform a system restore or restore from a known-good backup to recover files without paying the ransom.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A) This is a phishing attack; the technician should run a full antivirus scan.

    Why it's wrong here

    This scenario is a tech support scam, not a phishing attack: the user was socially engineered over the phone into granting remote access, which allowed the attacker to deploy ransomware. Running a full antivirus scan at this point is ineffective because the ransomware has already executed and encrypted files; antivirus tools can remove the malware but cannot reverse the encryption or recover the user's data.

  • ✓

    B) This is a tech support scam leading to ransomware; the technician should disconnect the computer from the network and then perform a system restore or restore from backup.

    Why this is correct

    This is the correct response because the user has fallen victim to a tech support scam, and the resulting ransomware infection must be contained immediately. Disconnecting the computer from the network prevents the ransomware from spreading to shared drives or other networked systems, which is a primary goal of ransomware propagation. After isolation, performing a system restore to a pre-infection restore point or restoring from a known-good backup is the safest way to recover files without paying the ransom, as the encryption is typically irreversible without the attacker's key.

  • ✗

    C) This is a ransomware attack; the technician should pay the ransom to recover files.

    Why it's wrong here

    While this is indeed a ransomware attack, paying the ransom is an unacceptable action because it funds criminal operations and provides no guarantee that the decryption key will be delivered or that files will be restored. Many victims who pay never recover their data, and paying twice is common. The correct approach is to restore from backups or use system restore, not to negotiate with cybercriminals.

  • ✗

    D) This is a vishing attack; the technician should change the user's password immediately.

    Why it's wrong here

    Vishing (voice phishing) is a social engineering technique used to trick victims into revealing sensitive information or performing actions, and it may be a component of this attack. However, the immediate crisis is the ransomware infection that resulted from the tech support scam, so changing the user's password will not decrypt the already-encrypted files or stop the encryption. The first priority is to isolate the machine from the network and then restore data from backup; a password change might be part of a later security cleanup, but it is not the urgent step.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.