220-1102 Security Practice Question
A security analyst discovers that an attacker has exploited a vulnerability to gain remote access to a file server. The analyst has identified active shell connections from the attacker's IP address. The server contains critical business data that cannot be lost, and there is a verified backup from the previous night. According to incident response best practices, what should the analyst do FIRST?
⚠ Common exam trap
Many exam-takers choose to kill processes first (B) because it seems like a direct technical fix, but they overlook that containment via network isolation is the immediate priority to stop active compromise and prevent data loss.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the server from the network
Disconnecting the server from the network (A) is the correct first step because it immediately stops the attacker's active shell connections and prevents further data exfiltration or lateral movement. In incident response, containment is prioritized over eradication or notification when there is an active threat, and since a verified backup exists, the risk of data loss is mitigated. This action follows the NIST SP 800-61 containment strategy, which aims to limit the scope of the incident before any other steps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disconnect the server from the network
Why this is correct
Disconnecting the server from the network is the correct first step because it isolates the compromised host, preventing the attacker from maintaining an active session, continuing lateral movement, or exfiltrating additional data. Network-level containment halts the attack in progress while preserving the system state for forensic analysis. This action directly addresses the active threat and should precede any investigative or recovery steps.
- ✗
Kill the remote shell processes on the server
Why it's wrong here
Killing the remote shell processes is a reactive measure that fails to address the underlying vulnerability or backdoor the attacker used to gain access, so they can simply spawn a new session afterward. Additionally, process termination does not stop other malicious activity such as credential dumping, data staging, or outbound network transfers already in progress. Proper containment requires isolating the host at the network level, not merely ending individual processes.
- ✗
Notify the company's management and legal department
Why it's wrong here
Notifying management and the legal department is an essential step, but it should occur after the immediate threat has been contained to prevent further damage and to provide a clearer incident picture. Premature notification without verified facts can lead to inaccurate reporting and may distract from time-critical response actions. Incident response frameworks consistently prioritize containment over stakeholder notification.
- ✗
Wipe the server and restore from the backup
Why it's wrong here
Wiping the server and restoring from backup destroys volatile and soft evidence needed to determine the root cause and scope of the compromise, violating forensic preservation principles. It also risks reintroducing the same vulnerability if the backup is from before the exploit was patched, allowing the attacker to return. Recovery should only proceed after containment and completion of the investigation.
Go deeper
Related to this question
Learn chapter
Data Classification Levels
Key term
Eradication
Eradication is the phase in incident response where the root cause of a security breach is completely removed from the system to prevent the attack from happening again.
Key term
Shell
A shell is a computer program that provides a user interface to access an operating system's services, typically by accepting text commands.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.