220-1102 Security Practice Question
A technician suspects a computer is infected with ransomware that has encrypted files and displays a ransom note. Which step should the technician take FIRST according to best practices for malware removal?
⚠ Common exam trap
The 220-1102 exam often tests the misconception that paying the ransom is a viable recovery option, but the correct first step is always containment through immediate network isolation to limit damage and preserve forensic evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the computer from the network
Disconnecting the computer from the network immediately isolates the ransomware, preventing it from communicating with its command-and-control (C2) server to exfiltrate data or encrypt additional network shares. This step also stops the ransomware from spreading laterally via SMB or other protocols, which is critical before any remediation begins.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pay the ransom to retrieve data
Why it's wrong here
Paying the ransom provides no cryptographic guarantee that the attacker will supply a valid decryption key; the file-encryption key may be destroyed or the malware may be a wiper that irreversibly corrupts data. Furthermore, payment funds the ransomware operation and marks the organization as willing to pay, increasing the likelihood of targeted follow-up attacks. This is why law enforcement and security frameworks universally recommend against payment as a technical response.
- ✓
Disconnect the computer from the network
Why this is correct
Disconnecting the computer from the network—whether by unplugging the Ethernet cable, disabling Wi-Fi and Bluetooth, or isolating it via a VLAN/subnet—is the immediate containment step that halts ransomware's lateral movement to SMB shares, mapped drives, and adjacent hosts. It also severs command-and-control (C2) communication, preventing the malware from receiving new encryption instructions or exfiltrating data. This containment must occur before any scanning or remediation to limit the blast radius and preserve forensic evidence.
- ✗
Run a full antivirus scan
Why it's wrong here
Running a full antivirus scan while the system remains network-connected is flawed because ransomware can continue encrypting files and spreading to network shares during the scan, while also altering its behavior to evade detection. Many modern ransomware strains are polymorphic or use fileless techniques that signature-based AV may miss, and the scan itself does nothing to stop the active encryption process. Antivirus tools are useful only after the host has been isolated and the ransomware's process has been terminated.
- ✗
Restore from backup
Why it's wrong here
Restoring from backup is a recovery action that assumes the malware has already been fully eradicated; if the ransomware is still active, it will immediately re-encrypt the restored files, rendering the restoration pointless. Additionally, you must verify that the backup itself is not infected or stored on a network mount that the ransomware can access, and that shadow copies have not been deleted by known techniques like vssadmin. Backups are a business continuity measure to be executed after containment, eradication, and validation of a clean system state.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A user reports that their Windows 10 computer shows a ransomware message demanding payment to decrypt files. According to standard incident response procedures, what should the technician do FIRST?
medium- A.Pay the ransom to quickly regain access to files
- ✓ B.Disconnect the computer from the network
- C.Run a full antivirus scan
- D.Restore files from a recent backup
Why B: Disconnecting the computer from the network is the immediate first step in incident response for ransomware. This containment action prevents the ransomware from encrypting additional files on network shares, communicating with its command-and-control (C2) server, or spreading laterally to other systems. The priority is to stop the attack from escalating before any remediation steps are taken.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.