Courseiva
hardMultiple ChoiceObjective-mapped

220-1102 Practice Question: A technician is troubleshooting a computer that…

A technician is troubleshooting a computer that has been infected with ransomware. The ransomware encrypted files and left a note demanding payment. After removing the malware, what is the most important step to prevent future infections?

⚠ Common exam trap

CompTIA often tests the misconception that technical controls alone (like reinstalling the OS or updating software) are sufficient, when in reality, user education and backup policies are the most critical steps to prevent future ransomware infections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement a strict backup policy and educate users on phishing

Ransomware often enters through phishing emails or unpatched vulnerabilities. While removing the malware is necessary, preventing future infections requires a combination of user education to avoid phishing attempts and a strict backup policy to ensure data can be restored without paying the ransom. Without addressing the root cause (user behavior and data resilience), the system remains vulnerable to reinfection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Reinstall the operating system

    Why it's wrong here

    While reinstalling the operating system is an effective method for eradicating existing malware, such as ransomware, it is a reactive measure that fails to prevent future incidents. This action does not address the fundamental issue of user susceptibility to social engineering tactics like phishing, which often lead to the initial infection. Without addressing the root cause of user behavior, the system remains vulnerable to reinfection from similar threats.

  • Update all software to the latest versions

    Why it's wrong here

    Updating all software to the latest versions is crucial for patching known security vulnerabilities and reducing the attack surface exploited by malware. However, this measure primarily mitigates exploits targeting software flaws, not human error. It does not prevent a user from actively downloading and executing a malicious attachment or clicking a deceptive link delivered via a phishing email, which is a common initial vector for ransomware.

  • Implement a strict backup policy and educate users on phishing

    Why this is correct

    Implementing a strict backup policy ensures that critical data can be restored in the event of a ransomware attack, significantly mitigating data loss and the pressure to pay a ransom. Concurrently, educating users on identifying and avoiding phishing attempts directly addresses the most common initial infection vector for ransomware. This proactive combination tackles both the consequences of an attack and the primary cause, offering a comprehensive defense.

  • Disable all browser plugins

    Why it's wrong here

    Disabling browser plugins can indeed reduce the attack surface by eliminating potential vulnerabilities or malicious extensions that could be exploited. However, this action primarily targets web-based threats and exploits that leverage browser functionality. It does not directly prevent ransomware infections that originate from email attachments or malicious links clicked by users, which often bypass browser-specific security mechanisms and execute directly on the operating system.

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.