220-1102 Operational Procedures Practice Question
A technician receives a report from a user that their workstation is displaying a ransomware note and files are being encrypted. The technician has already isolated the workstation from the network. According to incident response procedures, which of the following is the NEXT step the technician should take?
⚠ Common exam trap
220-1102 often tests the order of incident response steps; candidates may jump to remediation (scanning, restoring) instead of following the correct escalation procedure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Notify the appropriate internal security contact
According to incident response procedures, after isolating the affected system, the next step is to notify the appropriate internal security contact or team. This ensures that the incident is properly escalated and handled by trained personnel. Running antivirus scans, attempting decryption, or restoring from backup are remediation steps that should be guided by the security team and may destroy evidence if done prematurely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on the isolated workstation
Why it's wrong here
While antivirus scanning is a common eradication action, it is not the immediate next step after isolating the workstation because running it prematurely can modify filesystem metadata and quarantine artifacts that the security team needs for forensic analysis. Ransomware may also evade signature-based AV, giving a false sense of security while delaying mandatory incident notification. Escalation to the security contact must come first to preserve evidence and formally activate the incident response plan.
- ✗
Attempt to decrypt the files using online tools
Why it's wrong here
Attempting to decrypt files with online tools is dangerous because these services often require uploading samples of encrypted data or the ransom note, which could expose confidential information and introduce additional malware to the isolated environment. Without expert guidance, these tools can corrupt the already-compromised files, impairing future recovery efforts and destroying forensic value. The security team is the only source that should authorize or evaluate decryption methods, typically after the attack vector is identified.
- ✓
Notify the appropriate internal security contact
Why this is correct
Notifying the designated internal security contact is the correct action because it immediately triggers the formal incident response process, including documentation, evidence preservation, and coordinated investigation. This escalation ensures that legal and regulatory obligations are met and that containment, eradication, and recovery are performed in the correct order. All subsequent steps, including scanning, decryption, and restoration, must be directed or approved by that security team.
- ✗
Restore the user's files from the most recent backup
Why it's wrong here
Restoring from backup is a recovery-phase action that must never precede eradication and validation because the root cause may still be active, and the backup itself could contain infected or encrypted data that would re-infect the environment. Additionally, restoring files before the security team captures forensic evidence can overwrite critical timestamps and logs, compromising the investigation. The backup should only be restored after the system is confirmed clean and the security team has given the go-ahead.
Go deeper
Related to this question
Learn chapter
Backup Verification and Testing
Key term
Backup
A backup is a copy of computer data taken and stored separately so that the original data can be restored if it is lost, damaged, or corrupted.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.