hardMultiple ChoiceObjective-mapped
220-1102 Practice Question: A technician is troubleshooting a computer that…
A technician is troubleshooting a computer that has been infected with ransomware. The ransomware encrypted files and left a note demanding payment. After removing the malware, what is the most important step to prevent future infections?
⚠ Common exam trap
CompTIA often tests the misconception that technical controls alone (like reinstalling the OS or updating software) are sufficient, when in reality, user education and backup policies are the most critical steps to prevent future ransomware infections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a strict backup policy and educate users on phishing
Ransomware often enters through phishing emails or unpatched vulnerabilities. While removing the malware is necessary, preventing future infections requires a combination of user education to avoid phishing attempts and a strict backup policy to ensure data can be restored without paying the ransom. Without addressing the root cause (user behavior and data resilience), the system remains vulnerable to reinfection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reinstall the operating system
Why it's wrong here
While reinstalling the operating system is an effective method for eradicating existing malware, such as ransomware, it is a reactive measure that fails to prevent future incidents. This action does not address the fundamental issue of user susceptibility to social engineering tactics like phishing, which often lead to the initial infection. Without addressing the root cause of user behavior, the system remains vulnerable to reinfection from similar threats.
- ✗
Update all software to the latest versions
Why it's wrong here
Updating all software to the latest versions is crucial for patching known security vulnerabilities and reducing the attack surface exploited by malware. However, this measure primarily mitigates exploits targeting software flaws, not human error. It does not prevent a user from actively downloading and executing a malicious attachment or clicking a deceptive link delivered via a phishing email, which is a common initial vector for ransomware.
- ✓
Implement a strict backup policy and educate users on phishing
Why this is correct
Implementing a strict backup policy ensures that critical data can be restored in the event of a ransomware attack, significantly mitigating data loss and the pressure to pay a ransom. Concurrently, educating users on identifying and avoiding phishing attempts directly addresses the most common initial infection vector for ransomware. This proactive combination tackles both the consequences of an attack and the primary cause, offering a comprehensive defense.
- ✗
Disable all browser plugins
Why it's wrong here
Disabling browser plugins can indeed reduce the attack surface by eliminating potential vulnerabilities or malicious extensions that could be exploited. However, this action primarily targets web-based threats and exploits that leverage browser functionality. It does not directly prevent ransomware infections that originate from email attachments or malicious links clicked by users, which often bypass browser-specific security mechanisms and execute directly on the operating system.
Go deeper
Related to this question
Learn chapter
Malware Types and Removal
Key term
Phishing
Phishing is a type of cyber attack where criminals impersonate legitimate organizations or individuals to trick victims into revealing sensitive information such as passwords, credit card numbers, or personal data.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.