Courseiva
easyMultiple ChoiceObjective-mapped

220-1102 Practice Question: A small business owner calls for support because…

A small business owner calls for support because all of their files on the server have been renamed with a .encrypted extension, and a text file named 'README_TO_DECRYPT.txt' appears on the desktop demanding a Bitcoin payment. What is the first step the technician should take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disconnect the server from the network.

The first step in a ransomware incident is to isolate the infected system from the network to prevent the malware from spreading to other devices. Paying the ransom is discouraged as it does not guarantee data recovery and funds criminal activity. After isolation, the technician can assess the damage and attempt recovery from backups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Pay the ransom to get the decryption key immediately.

    Why it's wrong here

    Paying the ransom is strongly discouraged as it directly funds criminal enterprises, encouraging them to perpetuate further attacks against other organizations. There is no guarantee that the attackers will provide a working decryption key, or any key at all, after payment is made. Furthermore, paying the ransom often marks the victim as a successful target, potentially leading to future attacks or data exfiltration attempts. This action undermines cybersecurity efforts globally and does not resolve the underlying vulnerability.

  • Disconnect the server from the network.

    Why this is correct

    Immediately disconnecting the infected server from the network is the critical first step in containing a ransomware incident. This action prevents the ransomware from encrypting additional files on the local system, halts its ability to spread to other network shares, connected devices, or backup systems, and isolates the threat. By containing the infection, IT personnel can safely begin investigation, eradication, and recovery procedures without risking wider organizational impact.

  • Run a full antivirus scan on the server.

    Why it's wrong here

    Running a full antivirus scan on a server actively infected with ransomware, especially while still connected to the network, is not the initial recommended action. The ransomware may disable or evade the antivirus software, or the scan itself could inadvertently trigger further malicious activity, such as accelerated encryption or data deletion. Furthermore, a scan does not address the immediate need for containment, which is to stop the spread and prevent further damage before attempting eradication.

  • Restore files from a recent backup immediately.

    Why it's wrong here

    Restoring files from a recent backup immediately, without first isolating and thoroughly cleaning the infected system, is a premature and ineffective recovery step. If the ransomware or its persistent components are still active on the server, the newly restored data will likely be re-encrypted almost instantly. This not only wastes valuable time and resources but also risks corrupting the backup integrity if the infection spreads to the backup source during the restoration process.

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.