220-1102 Operational Procedures Practice Question
A small business experiences a ransomware attack that encrypted all files on a single workstation. The technician isolates the workstation, removes the malware using a bootable antivirus scanner, and restores the encrypted files from a verified cloud backup. According to best practices for incident response, which step should the technician perform NEXT?
⚠ Common exam trap
CompTIA often tests the order of incident response steps, and the trap here is that candidates confuse 'eradication' (removing malware) with 'post-incident activity' (documentation and review), thinking the process ends once the system is restored.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the incident and review lessons learned
After containment, eradication, and recovery (restoring from backup), the next step in the NIST incident response lifecycle is 'post-incident activity.' This involves documenting the incident and performing a lessons-learned review to improve future security posture. Skipping this step leaves the organization vulnerable to repeat attacks and fails to meet compliance or audit requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reimage the workstation to ensure all malware traces are removed
Why it's wrong here
The technician has already used a bootable scanner to remove malware and restored files from backup. Reimaging is typically done if the system cannot be cleaned thoroughly or if data restoration is not possible. Here, the system is already cleaned and functional, so reimaging is an extra step that may not be needed.
- ✓
Document the incident and review lessons learned
Why this is correct
After recovery, the incident response team should document everything that happened, evaluate the response effectiveness, and identify improvements. This step is crucial for strengthening future security posture and is a standard part of the incident response lifecycle.
- ✗
Notify local law enforcement about the ransomware attack
Why it's wrong here
While law enforcement may be notified in some cases, especially if sensitive data is involved, it is not an immediate requirement for every incident. The priority after recovery is to wrap up the incident internally before deciding on external notifications.
- ✗
Disable the user's account to prevent further access
Why it's wrong here
The user account was likely compromised, but the incident has been contained. Unless there is evidence of ongoing unauthorized access or malicious intent by the user, disabling the account is not necessary. The focus should be on restoring normal operations and learning from the incident.
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Backup
A backup is a copy of computer data taken and stored separately so that the original data can be restored if it is lost, damaged, or corrupted.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.