220-1102 Security Practice Question
A security technician observes that a user's workstation is making numerous outbound connections to a known malicious IP address. The technician confirms the system is infected with a trojan. According to the incident response process, after isolating the system from the network, what should the technician do NEXT?
⚠ Common exam trap
The 220-1102 exam often tests the principle that remediation (like wiping or scanning) must never precede evidence preservation in the incident response process, tempting candidates to jump to fixing the problem immediately.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preserve evidence and create a forensic image
After isolating the infected system from the network, the next step in the incident response process is to preserve evidence and create a forensic image. This ensures that volatile data and the current state of the system are captured for analysis, chain of custody is maintained, and legal or investigative requirements are met before any remediation steps like wiping or scanning are performed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wipe the hard drive and reinstall the operating system
Why it's wrong here
Wiping the hard drive and reinstalling the operating system is an overtly destructive action that permanently destroys all potential digital evidence, including the trojan binary, registry artifacts, event logs, and the artifacts needed to identify the initial infection vector. This violates core forensic preservation principles, breaks the chain of custody, makes root cause analysis impossible, and is not an accepted step after isolating a compromised workstation.
- ✗
Run a full antivirus scan to remove the trojan
Why it's wrong here
Running a full antivirus scan will modify the system's file metadata, update access and creation timestamps, quarantine or delete the malware, and write new log entries, thereby altering the exact evidence that must be preserved for investigation. This tampering prevents forensic analysts from reconstructing the original state of the infection and could even trigger the trojan to destroy additional data or evade detection. The correct procedure is to preserve evidence first, not to alter the system with automated remediation tools.
- ✓
Preserve evidence and create a forensic image
Why this is correct
Preserving evidence and creating a forensic image is the mandatory next step after isolating the workstation because it captures the exact drive state, including deleted files, unallocated space, and the trojan artifact, for analysis without changing the original media. A bit-for-bit image with a verified cryptographic hash preserves data integrity and establishes a clean chain of custody for potential legal or disciplinary proceedings. This approach enables analysts to determine the attack vector, scope of compromise, and any data exfiltration while the system remains quarantined.
- ✗
Notify the user that the issue is resolved
Why it's wrong here
Notifying the user that the issue is resolved is premature and inappropriate because containment only isolates the system; eradication, recovery, and verification have not yet been completed, and the full scope of the infection is still unknown. Such a message could cause the user to resume normal activity or discard the workstation, jeopardizing critical evidence and allowing the trojan to persist in the environment. Professional incident response requires completing forensic analysis, removing the threat, and validating system integrity before any resolution is communicated.
Go deeper
Related to this question
Learn chapter
Data Classification Levels
Key term
Chain of custody
Chain of custody is a documented process that tracks the handling, transfer, and possession of evidence or digital assets from the moment they are collected until they are presented in court or used in an investigation.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.