mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: A small business owner reports that all their…
A small business owner reports that all their Microsoft Office documents are now encrypted with a '.crypt' extension and a ransom note demands payment in cryptocurrency. They have a backup from last week stored on an external drive that was disconnected after the backup. What is the best recovery strategy?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restore the files from the disconnected external backup after removing the malware.
Since the backup is offline and not encrypted, restoring from it is the safest and most reliable recovery method. Paying the ransom is discouraged as it funds criminals and may not work. The system should be cleaned of malware before restoration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pay the ransom to obtain the decryption key.
Why it's wrong here
Paying the ransom is strongly discouraged as it directly funds criminal organizations and does not guarantee the successful recovery of encrypted files. Ransomware attackers frequently fail to provide a working decryption key, or any key at all, even after payment. Furthermore, complying with ransom demands signals to attackers that the victim is a viable target, potentially leading to repeat attacks or sharing the victim's information with other malicious actors.
- ✓
Restore the files from the disconnected external backup after removing the malware.
Why this is correct
Restoring files from a disconnected external backup is the most reliable and secure method for data recovery after a ransomware attack. Since the backup medium was offline, it remained immune to the encryption performed by the malware, preserving the integrity of the data. After thoroughly cleaning the infected system to ensure all traces of malware are eradicated, the unencrypted data can be safely restored, minimizing downtime and data loss.
- ✗
Run a decryptor tool downloaded from a random website.
Why it's wrong here
Downloading and running a decryptor tool from an untrusted or random website is extremely risky and generally ineffective against modern ransomware. Such tools often contain additional malware, spyware, or viruses that can further compromise the system's security and data integrity. Moreover, most ransomware variants use unique encryption keys, rendering generic or outdated decryptors useless, and potentially causing irreversible damage to the encrypted files.
- ✗
Use System Restore to revert the system to a previous state.
Why it's wrong here
While System Restore can revert system files, installed applications, and registry settings to a previous state, it explicitly does not recover or restore personal user files such as documents, photos, or videos. Ransomware specifically targets and encrypts these personal data files, which remain encrypted even after a System Restore operation. Therefore, System Restore is ineffective for recovering the data lost to ransomware encryption.
Go deeper
Related to this question
Learn chapter
Malware Types and Removal
Key term
Backup
A backup is a copy of computer data taken and stored separately so that the original data can be restored if it is lost, damaged, or corrupted.
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1202
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A user reports that their computer is infected with a virus that has encrypted all their personal files and left a text file with instructions to pay a ransom. The technician has verified the infection is ransomware. The company has a backup policy. What is the best course of action to recover the data?
hard- A.Pay the ransom and hope the decryption key is provided.
- B.Use a ransomware decryption tool from a reputable source.
- ✓ C.Restore the files from a recent backup after removing the malware.
- D.Reinstall the operating system and hope the files become accessible.
Why C: The company has a backup policy, meaning a recent, clean backup should exist. Restoring from backup after removing the ransomware ensures data recovery without paying criminals or relying on unreliable decryption tools. This aligns with best practices for ransomware incidents: isolate, remove, then restore from verified backups.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.