Courseiva
easyMultiple Choice

220-1102 Practice Question: A small business owner calls for support because…

A small business owner calls for support because all of their files on the server have been renamed with a .encrypted extension, and a text file named 'README_TO_DECRYPT.txt' appears on the desktop demanding a Bitcoin payment. What is the first step the technician should take?

⚠ Common exam trap

220-1202 often tests the order of incident response steps — candidates pick 'restore from backup' or 'run antivirus' because those feel productive, but containment (network isolation) must always be the first action to stop active spread.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disconnect the server from the network.

Ransomware encrypts files and often maintains a command-and-control channel to spread laterally across the network. Disconnecting the server from the network immediately isolates it, preventing further encryption of shared drives and blocking communication with the attacker's infrastructure. This containment step must precede any scanning, restoration, or negotiation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pay the ransom to get the decryption key immediately.

    Why it's wrong here

    Paying the ransom is strongly discouraged as it directly funds criminal enterprises, encouraging them to perpetuate further attacks against other organizations. There is no guarantee that the attackers will provide a working decryption key, or any key at all, after payment is made. Furthermore, paying the ransom often marks the victim as a successful target, potentially leading to future attacks or data exfiltration attempts. This action undermines cybersecurity efforts globally and does not resolve the underlying vulnerability.

  • ✓

    Disconnect the server from the network.

    Why this is correct

    Immediately disconnecting the infected server from the network is the critical first step in containing a ransomware incident. This action prevents the ransomware from encrypting additional files on the local system, halts its ability to spread to other network shares, connected devices, or backup systems, and isolates the threat. By containing the infection, IT personnel can safely begin investigation, eradication, and recovery procedures without risking wider organizational impact.

  • ✗

    Run a full antivirus scan on the server.

    Why it's wrong here

    Running a full antivirus scan on a server actively infected with ransomware, especially while still connected to the network, is not the initial recommended action. The ransomware may disable or evade the antivirus software, or the scan itself could inadvertently trigger further malicious activity, such as accelerated encryption or data deletion. Furthermore, a scan does not address the immediate need for containment, which is to stop the spread and prevent further damage before attempting eradication.

  • ✗

    Restore files from a recent backup immediately.

    Why it's wrong here

    Restoring files from a recent backup immediately, without first isolating and thoroughly cleaning the infected system, is a premature and ineffective recovery step. If the ransomware or its persistent components are still active on the server, the newly restored data will likely be re-encrypted almost instantly. This not only wastes valuable time and resources but also risks corrupting the backup integrity if the infection spreads to the backup source during the restoration process.

About these practice questions

This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.