Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A security analyst discovers that a user's workstation has been infected with a keylogger delivered via a phishing email. The keylogger has captured the user's login credentials for several corporate systems. According to incident response best practices, which of the following should the analyst do FIRST?

⚠ Common exam trap

CompTIA often tests the principle that containment (isolation) must precede eradication (antivirus scans) and recovery (password resets), tempting candidates to jump to a reactive step like password resets or scanning instead of stopping the active threat first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Isolate the workstation from the network

Isolating the workstation from the network (C) is the first priority in incident response to contain the threat and prevent the attacker from using the captured credentials to access other corporate systems or exfiltrate data. This aligns with the 'Containment' phase of the NIST SP 800-61 incident response lifecycle, which must occur before eradication or recovery steps like password resets or antivirus scans.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Notify law enforcement about the phishing attack

    Why it's wrong here

    Contacting law enforcement is a legal and regulatory step that takes time and does nothing to halt the active keylogger. While authorities may need to be involved later for a criminal investigation and evidence preservation, the immediate technical priority is containing the compromise. Every moment the workstation remains connected, the attacker can continue harvesting keystrokes and exfiltrating sensitive data.

  • ✗

    Reset all the user's passwords across all systems

    Why it's wrong here

    Resetting all passwords before isolating the workstation is risky because if the attacker is actively monitoring keystrokes, they will simply capture the new credentials as they are typed. The compromised workstation would act as a proxy for the attacker, extending their access to every account reset from it. Containment first ensures that when passwords are changed, the new secrets are not delivered straight to the command-and-control server.

  • ✓

    Isolate the workstation from the network

    Why this is correct

    Isolating the workstation by unplugging the network cable or disabling the wireless adapter severs the command-and-control channel that the keylogger relies on, halting data exfiltration and preventing lateral movement to other systems. This containment step is the immediate priority in incident response because it stops the active loss of confidential information while preserving the system state for further forensic analysis. After isolation, the system can be safely analyzed and remediated.

  • ✗

    Run a full antivirus scan on the workstation

    Why it's wrong here

    Running a full antivirus scan is part of the eradication phase, but while the system is still connected to the network, the attacker can continue to receive keylogged data in real time. Additionally, many rootkits and keyloggers are designed to hide from or evade standard AV products, so a scan may give a false sense of security. The correct sequence is to contain the system first, then scan and remove the malware from a position where no further data is being lost.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.