220-1102 Operational Procedures Practice Question
A help desk technician receives a ticket from a user reporting that their computer is infected with ransomware. All files are encrypted, and a ransom note demands payment. According to the company's incident response policy, what is the FIRST action the technician should take?
⚠ Common exam trap
A common mix-up: candidates think paying the ransom is a quick fix to recover data, but the CompTIA 220-1102 exam emphasizes that the first step in incident response is always containment, and paying ransoms is never a recommended or policy-compliant action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the computer from the network.
Disconnecting the computer from the network is the first action because it immediately contains the ransomware, preventing it from spreading laterally to other systems via SMB, RDP, or mapped drives. This aligns with the containment phase of the incident response process, which must occur before any analysis or remediation. Paying the ransom is explicitly discouraged by policy, as it funds criminal activity and does not guarantee decryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disconnect the computer from the network.
Why this is correct
Disconnecting the computer from the network is the immediate first step in incident response because it contains the ransomware outbreak. By physically unplugging the Ethernet cable or disabling the wireless adapter, you sever the malicious process’s ability to communicate with its command-and-control server, spread to file shares, or encrypt additional mapped drives. This containment action also preserves volatile evidence in memory, which is lost if you power down or perform other operations, and it does not require any prior analysis.
- ✗
Pay the ransom to retrieve the files.
Why it's wrong here
Paying the ransom is never a recommended remediation because it directly funds criminal organizations and does not guarantee that you will recover any files. Ransomware operators may supply a broken decryption tool, demand additional payments, or simply not respond, leaving you with the same encrypted data and no technical recourse. In many jurisdictions, ransom payments to sanctioned groups may also violate OFAC regulations, so this choice creates legal risk without solving the underlying infection.
- ✗
Run a full antivirus scan on the computer.
Why it's wrong here
Running a full antivirus scan at this stage is premature because the machine remains connected, allowing ransomware to continue encrypting shared volumes or exfiltrating data while the scanner is running. Antivirus operations also read and write to disks, changing file access timestamps and metadata that are critical for forensic analysis, and many modern ransomware strains are designed to disable or evade detection by endpoint protection. A scan should only be performed after the host is isolated, and even then its primary value is identifying the infection vector, not recovering already-encrypted files.
- ✗
Restore files from the most recent backup.
Why it's wrong here
Restoring files from the most recent backup is an appropriate recovery step, but doing it before containment and investigation risks reintroducing the infection or restoring backup copies that were themselves compromised. If the original vulnerability that allowed the ransomware to enter remains unpatched, the system will simply be re-encrypted after restoration. Furthermore, without isolating the machine first, the restore process may write data over encrypted volumes while the malicious process is still active, wasting time and failing to restore integrity; the correct sequence is contain, eradicate the threat, then restore from a verified clean backup.
Go deeper
Related to this question
Learn chapter
SOHO Network Security
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Decryption
Decryption is the process of converting encrypted or scrambled data back into its original, readable form using a specific key or method.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.