Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A security audit reveals that an employee's laptop is infected with a rootkit that has been logging keystrokes for the past month. According to standard malware removal best practices, what should the technician do FIRST?

⚠ Common exam trap

The trap here is that candidates often jump to remediation (scanning or restoring) without first containing the threat, failing to recognize that a rootkit's persistence and network activity require immediate isolation to prevent data loss and further compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disconnect the laptop from the network

The first step in standard malware removal best practices is to contain the infection by disconnecting the laptop from the network. This prevents the rootkit from communicating with its command-and-control server, stops further keystroke data exfiltration, and blocks lateral movement to other systems. Even before scanning or remediation, isolation is critical to limit damage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Disconnect the laptop from the network

    Why this is correct

    Disconnecting the laptop from the network is the immediate containment step because active malware, especially C2 (command-and-control) agents or ransomware, can continue exfiltrating data, encrypting files, or spreading laterally across the LAN/VPN the moment it has connectivity. Cutting the network interface (Ethernet, Wi-Fi, or cellular) halts ongoing data theft and prevents the infection from reaching other hosts, making every subsequent remediation step safer and more reliable. Even if the malware has already established persistence, isolation is the only action that definitively stops real-time communication with the attacker while preserving forensic evidence.

  • ✗

    Run a full antivirus scan in Safe Mode

    Why it's wrong here

    Running a full antivirus scan in Safe Mode is a valid post-isolation detection technique, but it is not the first response because the system remains connected to the network during the scan, allowing data exfiltration or lateral movement to continue. More importantly, modern malware—especially rootkits and bootkits—can hide from the OS kernel, and Safe Mode may not load the necessary drivers or network stack in a way that matches the infection's evasion tactics, leading to false negatives. The scan should only be attempted after the laptop is physically or logically isolated, and even then, its results are provisional; a definitive clean state often requires reimaging.

  • ✗

    Perform a System Restore to a point before the infection

    Why it's wrong here

    Performing a System Restore to a point before the infection is ineffective as a first step because System Restore only reverts registry keys and protected system files, leaving user data, installed drivers, and many malware persistence mechanisms—like scheduled tasks, services, or startup entries in non-protected locations—untouched. Rootkits or worms that reside in the boot sector or firmware survive the restore process entirely, and the restore point itself may have been created after the infection, meaning the 'clean' state is actually still compromised. System Restore also does nothing to halt active network communication, so the attacker can continue stealing data while the restore runs, and it can even reintroduce older vulnerabilities if the restore point is outdated.

  • ✗

    Reimage the laptop from a known-good backup

    Why it's wrong here

    Reimaging the laptop from a known-good backup is the most thorough remediation because it wipes the compromised partition and reinstalls the OS and applications fresh, eliminating all malware traces, but performing it before isolation is a critical security failure. During the imaging process, the original infected drive is still attached, and if the laptop is networked, the malware can continue to beacon out or spread to file shares; worse, if the backup image is restored over the network (e.g., from a network share), the infection could contaminate the restore source or be replayed during the restoration. The correct sequence is to isolate first, then preserve evidence (forensic copy), and only then reimage—making reimaging a later step, not the initial action.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.