Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A technician receives a report from a user that their workstation is displaying a ransomware note and files are being encrypted. The technician has already isolated the workstation from the network. According to incident response procedures, which of the following is the NEXT step the technician should take?

⚠ Common exam trap

220-1102 often tests the order of incident response steps; candidates may jump to remediation (scanning, restoring) instead of following the correct escalation procedure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Notify the appropriate internal security contact

According to incident response procedures, after isolating the affected system, the next step is to notify the appropriate internal security contact or team. This ensures that the incident is properly escalated and handled by trained personnel. Running antivirus scans, attempting decryption, or restoring from backup are remediation steps that should be guided by the security team and may destroy evidence if done prematurely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a full antivirus scan on the isolated workstation

    Why it's wrong here

    While antivirus scanning is a common eradication action, it is not the immediate next step after isolating the workstation because running it prematurely can modify filesystem metadata and quarantine artifacts that the security team needs for forensic analysis. Ransomware may also evade signature-based AV, giving a false sense of security while delaying mandatory incident notification. Escalation to the security contact must come first to preserve evidence and formally activate the incident response plan.

  • ✗

    Attempt to decrypt the files using online tools

    Why it's wrong here

    Attempting to decrypt files with online tools is dangerous because these services often require uploading samples of encrypted data or the ransom note, which could expose confidential information and introduce additional malware to the isolated environment. Without expert guidance, these tools can corrupt the already-compromised files, impairing future recovery efforts and destroying forensic value. The security team is the only source that should authorize or evaluate decryption methods, typically after the attack vector is identified.

  • ✓

    Notify the appropriate internal security contact

    Why this is correct

    Notifying the designated internal security contact is the correct action because it immediately triggers the formal incident response process, including documentation, evidence preservation, and coordinated investigation. This escalation ensures that legal and regulatory obligations are met and that containment, eradication, and recovery are performed in the correct order. All subsequent steps, including scanning, decryption, and restoration, must be directed or approved by that security team.

  • ✗

    Restore the user's files from the most recent backup

    Why it's wrong here

    Restoring from backup is a recovery-phase action that must never precede eradication and validation because the root cause may still be active, and the backup itself could contain infected or encrypted data that would re-infect the environment. Additionally, restoring files before the security team captures forensic evidence can overwrite critical timestamps and logs, compromising the investigation. The backup should only be restored after the system is confirmed clean and the security team has given the go-ahead.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.