220-1102 Security Practice Question
A security incident has occurred. A malware infection was detected on a server that stores encrypted customer PII. The server was immediately isolated from the network. According to the incident response plan, which step should the technician take NEXT after preserving evidence?
⚠ Common exam trap
Candidates often confuse the urgency of containment with the need for root cause analysis, mistakenly choosing to reimage or reset passwords immediately, which violates the forensic principle of preserving the chain of custody and can lead to incomplete remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Determine the root cause
After isolating the server and preserving evidence, the next step in the incident response process is to determine the root cause. This aligns with the CompTIA A+ 220-1102 framework, which follows the NIST SP 800-61 incident response lifecycle: Preparation, Detection & Analysis, Containment, Eradication & Recovery, and Post-Incident Activity. Determining the root cause (e.g., identifying the specific vulnerability or attack vector) is essential before any eradication or recovery actions, such as reimaging or password resets, to ensure the same breach does not recur.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify law enforcement
Why it's wrong here
Notifying law enforcement is not the immediate next step because the incident response process requires internal triage, evidence preservation, and root-cause identification before external entities are involved. Legal notification is governed by regulatory or contractual obligations and should be coordinated with management and counsel, not performed prematurely. Furthermore, improper or hasty external communication can compromise the chain of custody for forensic evidence.
- ✗
Reimage the server
Why it's wrong here
Reimaging the server is a destructive recovery action that wipes the filesystem and, in many cases, the operating system, thereby destroying volatile data such as memory contents, running processes, and other forensic artifacts critical to understanding the infection. Eradication and system restoration should occur only after the root cause has been confirmed and forensic evidence has been collected, because reimaging without analysis risks missing persistence mechanisms that could reinfect the environment, including other hosts on the network.
- ✓
Determine the root cause
Why this is correct
Determining the root cause is the correct immediate step because incident response demands understanding the attack vector, entry point, propagation path, and persistence mechanisms before taking corrective action. This involves examining logs, system artifacts, network traffic, and any malware samples to identify how the infection started, which is essential for effective containment, eradication, and prevention of recurrence. Skipping root-cause analysis often leads to incomplete remediation and repeated compromise, as the same vulnerability remains unaddressed.
- ✗
Reset all user passwords
Why it's wrong here
Resetting all user passwords is a containment or eradication measure, not an immediate analysis step, and performing it prematurely may lock out legitimate users and disrupt business operations while the actual attack vector remains unresolved. Password resets address credential-based lateral movement but do nothing to remove malware, patch a vulnerable service, or block the original infection mechanism. Without determining the root cause, attackers may still retain persistence through other means such as backdoors or session tokens, making the password reset ineffective and counterproductive.
Go deeper
Related to this question
Learn chapter
Incident Response for A+
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.