Courseiva
Operational Procedures →hardMultiple Choice

220-1102 Operational Procedures Practice Question

A security technician has confirmed that a user's workstation is infected with ransomware that has encrypted local files. The technician immediately isolated the system by disconnecting the network cable and then created a forensic image of the hard drive for evidence. According to standard incident response procedures, what should the technician do NEXT?

⚠ Common exam trap

Many exam-takers confuse the order of the 'Eradication' and 'Recovery' phases, often jumping to restore data from backup (Option B) before removing the active ransomware, which would allow the malware to re-encrypt the restored files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remove the ransomware from the workstation

After isolating the system and preserving evidence via forensic imaging, the next step in standard incident response procedures is to contain and eradicate the threat. Removing the ransomware from the workstation prevents further encryption or lateral movement, and it aligns with the 'Eradication' phase of the NIST SP 800-61 incident response lifecycle. The technician must eliminate the malware before any recovery or root cause analysis can safely proceed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Report the incident to management and legal

    Why it's wrong here

    Reporting to management and legal is a critical communication step, but it falls outside the immediate technical response sequence. After containment and evidence collection, the next phase is eradication, which removes the active ransomware from the system. Legal notifications may be required by breach notification laws, but delaying eradication to report first leaves the malicious executable and any associated persistence mechanisms in place, prolonging the risk of further encryption or lateral movement.

  • ✗

    Restore user data from the most recent backup

    Why it's wrong here

    Restoring data from a backup is part of the recovery phase, which must occur only after the ransomware has been fully eradicated. If you restore user data while the ransomware or its persistence mechanisms are still active, the restore process may reintroduce the threat, cause immediate re-encryption, or re-infect the system through compromised even without new encryption, the malicious code could tamper with the restored files. Eradication ensures the workstation is clean before any recovery activities, including backup restoration, are attempted.

  • ✗

    Identify the root cause of the ransomware infection

    Why it's wrong here

    Root cause analysis is a critical step, but it typically takes place after recovery during the 'lessons learned' phase. The immediate next step after containment and evidence is to eradicate the malware from the affected system.

  • ✓

    Remove the ransomware from the workstation

    Why this is correct

    Removing the ransomware from the workstation is the correct next step because it aligns with the eradication phase of incident response. This involves deleting the ransomware binaries, associated scripts, and registry entries, and using trusted antivirus or endpoint detection and response (EDR) tools to confirm the system is clean. Only after eradication is complete can you safely perform recovery steps such as restoring from backups, as any remaining malware could immediately re-encrypt restored data or allow persistent attacker access.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.