easyMultiple Choice
220-1102 Practice Question: A small business owner calls for support because…
A small business owner calls for support because all of their files on the server have been renamed with a .encrypted extension, and a text file named 'README_TO_DECRYPT.txt' appears on the desktop demanding a Bitcoin payment. What is the first step the technician should take?
⚠ Common exam trap
220-1202 often tests the order of incident response steps — candidates pick 'restore from backup' or 'run antivirus' because those feel productive, but containment (network isolation) must always be the first action to stop active spread.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the server from the network.
Ransomware encrypts files and often maintains a command-and-control channel to spread laterally across the network. Disconnecting the server from the network immediately isolates it, preventing further encryption of shared drives and blocking communication with the attacker's infrastructure. This containment step must precede any scanning, restoration, or negotiation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pay the ransom to get the decryption key immediately.
Why it's wrong here
Paying the ransom is strongly discouraged as it directly funds criminal enterprises, encouraging them to perpetuate further attacks against other organizations. There is no guarantee that the attackers will provide a working decryption key, or any key at all, after payment is made. Furthermore, paying the ransom often marks the victim as a successful target, potentially leading to future attacks or data exfiltration attempts. This action undermines cybersecurity efforts globally and does not resolve the underlying vulnerability.
- ✓
Disconnect the server from the network.
Why this is correct
Immediately disconnecting the infected server from the network is the critical first step in containing a ransomware incident. This action prevents the ransomware from encrypting additional files on the local system, halts its ability to spread to other network shares, connected devices, or backup systems, and isolates the threat. By containing the infection, IT personnel can safely begin investigation, eradication, and recovery procedures without risking wider organizational impact.
- ✗
Run a full antivirus scan on the server.
Why it's wrong here
Running a full antivirus scan on a server actively infected with ransomware, especially while still connected to the network, is not the initial recommended action. The ransomware may disable or evade the antivirus software, or the scan itself could inadvertently trigger further malicious activity, such as accelerated encryption or data deletion. Furthermore, a scan does not address the immediate need for containment, which is to stop the spread and prevent further damage before attempting eradication.
- ✗
Restore files from a recent backup immediately.
Why it's wrong here
Restoring files from a recent backup immediately, without first isolating and thoroughly cleaning the infected system, is a premature and ineffective recovery step. If the ransomware or its persistent components are still active on the server, the newly restored data will likely be re-encrypted almost instantly. This not only wastes valuable time and resources but also risks corrupting the backup integrity if the infection spreads to the backup source during the restoration process.
Go deeper
Related to this question
Learn chapter
Linux File System Structure
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.