Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A small business experiences a ransomware attack that encrypted all files on a single workstation. The technician isolates the workstation, removes the malware using a bootable antivirus scanner, and restores the encrypted files from a verified cloud backup. According to best practices for incident response, which step should the technician perform NEXT?

⚠ Common exam trap

CompTIA often tests the order of incident response steps, and the trap here is that candidates confuse 'eradication' (removing malware) with 'post-incident activity' (documentation and review), thinking the process ends once the system is restored.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the incident and review lessons learned

After containment, eradication, and recovery (restoring from backup), the next step in the NIST incident response lifecycle is 'post-incident activity.' This involves documenting the incident and performing a lessons-learned review to improve future security posture. Skipping this step leaves the organization vulnerable to repeat attacks and fails to meet compliance or audit requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reimage the workstation to ensure all malware traces are removed

    Why it's wrong here

    The technician has already used a bootable scanner to remove malware and restored files from backup. Reimaging is typically done if the system cannot be cleaned thoroughly or if data restoration is not possible. Here, the system is already cleaned and functional, so reimaging is an extra step that may not be needed.

  • ✓

    Document the incident and review lessons learned

    Why this is correct

    After recovery, the incident response team should document everything that happened, evaluate the response effectiveness, and identify improvements. This step is crucial for strengthening future security posture and is a standard part of the incident response lifecycle.

  • ✗

    Notify local law enforcement about the ransomware attack

    Why it's wrong here

    While law enforcement may be notified in some cases, especially if sensitive data is involved, it is not an immediate requirement for every incident. The priority after recovery is to wrap up the incident internally before deciding on external notifications.

  • ✗

    Disable the user's account to prevent further access

    Why it's wrong here

    The user account was likely compromised, but the incident has been contained. Unless there is evidence of ongoing unauthorized access or malicious intent by the user, disabling the account is not necessary. The focus should be on restoring normal operations and learning from the incident.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.