Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A security analyst is reviewing logs after a malware infection on a user's workstation. The logs show that the malware attempted to contact multiple external IP addresses on port 445 (SMB) and also made several attempts to write to files with extensions like .docx, .xlsx, .pdf. The antivirus prevented the malware from executing but the analyst wants to contain the threat. According to incident response best practices, what should the analyst do FIRST?

⚠ Common exam trap

It's easy for candidates to confuse eradication (running a scan) with containment (isolating the system), leading them to choose a full antivirus scan first instead of disconnecting the network.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disconnect the workstation from the network

Disconnecting the workstation from the network is the correct first step because it immediately stops the malware from communicating with external command-and-control (C2) servers over port 445 (SMB) and prevents further lateral movement or data exfiltration. Even though the antivirus prevented execution, the logs show active network connections, meaning the threat is still present and could spread. Containment before eradication is a core incident response principle, and isolation via network disconnection is the fastest way to achieve it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Disconnect the workstation from the network

    Why this is correct

    Physically unplugging the Ethernet cable or disabling the NIC immediately severs Layer 2/3 connectivity, halting command-and-control beaconing and blocking lateral movement via SMB/WMI/PsExec. This action also stops data exfiltration while preserving the current memory and disk state for forensic evidence collection. In incident response, containment precedes eradication, so isolating the host is the first priority.

  • ✗

    Run a full antivirus scan

    Why it's wrong here

    Running a full antivirus scan before isolating the host allows the malware to continue communicating and spreading during the lengthy scan, defeating the purpose of containment. AV scans also alter file access times and may trigger anti-forensics behavior that corrupts evidence. The proper sequence is to disconnect the machine first; scanning belongs to the eradication phase after the system is offline.

  • ✗

    Change the user's password

    Why it's wrong here

    Resetting the password does not terminate an attacker's already-established authenticated session, and any process spawned with the user's token remains valid on the compromised host. Malware may have cached credentials or a Golden Ticket that survives a simple password change, enabling continued domain access. This step is important post-containment to flush compromised accounts, but it is not a containment control.

  • ✗

    Reimage the workstation

    Why it's wrong here

    Reimaging destroys volatile evidence and artifacts (e.g., network connections, memory-resident malware, encryption keys) needed for root cause analysis, and it does nothing to stop the malware from propagating while the machine remains connected. A network-based reimage process could even reintroduce the infection if the source images or SMB shares are compromised. Reimaging is a final remediation action after isolation and forensic preservation.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.