220-1102 Security Practice Question
A security audit reveals that an employee's laptop is infected with a rootkit that has been logging keystrokes for the past month. According to standard malware removal best practices, what should the technician do FIRST?
⚠ Common exam trap
The trap here is that candidates often jump to remediation (scanning or restoring) without first containing the threat, failing to recognize that a rootkit's persistence and network activity require immediate isolation to prevent data loss and further compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the laptop from the network
The first step in standard malware removal best practices is to contain the infection by disconnecting the laptop from the network. This prevents the rootkit from communicating with its command-and-control server, stops further keystroke data exfiltration, and blocks lateral movement to other systems. Even before scanning or remediation, isolation is critical to limit damage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disconnect the laptop from the network
Why this is correct
Disconnecting the laptop from the network is the immediate containment step because active malware, especially C2 (command-and-control) agents or ransomware, can continue exfiltrating data, encrypting files, or spreading laterally across the LAN/VPN the moment it has connectivity. Cutting the network interface (Ethernet, Wi-Fi, or cellular) halts ongoing data theft and prevents the infection from reaching other hosts, making every subsequent remediation step safer and more reliable. Even if the malware has already established persistence, isolation is the only action that definitively stops real-time communication with the attacker while preserving forensic evidence.
- ✗
Run a full antivirus scan in Safe Mode
Why it's wrong here
Running a full antivirus scan in Safe Mode is a valid post-isolation detection technique, but it is not the first response because the system remains connected to the network during the scan, allowing data exfiltration or lateral movement to continue. More importantly, modern malware—especially rootkits and bootkits—can hide from the OS kernel, and Safe Mode may not load the necessary drivers or network stack in a way that matches the infection's evasion tactics, leading to false negatives. The scan should only be attempted after the laptop is physically or logically isolated, and even then, its results are provisional; a definitive clean state often requires reimaging.
- ✗
Perform a System Restore to a point before the infection
Why it's wrong here
Performing a System Restore to a point before the infection is ineffective as a first step because System Restore only reverts registry keys and protected system files, leaving user data, installed drivers, and many malware persistence mechanisms—like scheduled tasks, services, or startup entries in non-protected locations—untouched. Rootkits or worms that reside in the boot sector or firmware survive the restore process entirely, and the restore point itself may have been created after the infection, meaning the 'clean' state is actually still compromised. System Restore also does nothing to halt active network communication, so the attacker can continue stealing data while the restore runs, and it can even reintroduce older vulnerabilities if the restore point is outdated.
- ✗
Reimage the laptop from a known-good backup
Why it's wrong here
Reimaging the laptop from a known-good backup is the most thorough remediation because it wipes the compromised partition and reinstalls the OS and applications fresh, eliminating all malware traces, but performing it before isolation is a critical security failure. During the imaging process, the original infected drive is still attached, and if the laptop is networked, the malware can continue to beacon out or spread to file shares; worse, if the backup image is restored over the network (e.g., from a network share), the infection could contaminate the restore source or be replayed during the restoration. The correct sequence is to isolate first, then preserve evidence (forensic copy), and only then reimage—making reimaging a later step, not the initial action.
Go deeper
Related to this question
Learn chapter
SOHO Network Security
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.