easyMultiple Choice
220-1102 Practice Question: A user calls the help desk because their…
A user calls the help desk because their workstation is running very slowly and they notice unusual network activity. You suspect ransomware. What should you do first to contain the threat?
⚠ Common exam trap
CompTIA A+ emphasizes that containment (isolation) must precede remediation (scanning, backup, or boot changes) in incident response. The trap here is that candidates mistakenly choose a reactive remediation step like running a scan or backing up files, which can worsen the spread or data loss.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the workstation from the network immediately.
Disconnecting the workstation from the network immediately is the correct first step because ransomware often uses network propagation mechanisms (e.g., SMB, RDP) to encrypt shared drives and spread to other systems. By isolating the machine at the physical or logical layer, you prevent lateral movement and further encryption of network resources, which is the primary containment priority in a suspected ransomware incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on the affected workstation.
Why it's wrong here
Scanning lets the malware keep running and encrypting during the scan, and many strains disable or evade the installed antivirus. It is tempting because a scan is the standard response to suspected infection, and it would be correct once the host is already isolated from the network and storage.
- ✓
Disconnect the workstation from the network immediately.
Why this is correct
Severing the network connection halts command-and-control traffic and lateral movement or encryption of shared resources, containing ransomware before eradication. It is the immediate first action; powering off or remediating in place risks further spread and destroys volatile evidence.
- ✗
Back up all files to an external drive before taking action.
Why it's wrong here
Copying files to external media spreads the infection and preserves encrypted data rather than stopping the encryption process. It is tempting because preserving evidence and data feels prudent, and backing up would be correct before remediation once the machine is disconnected and the threat is contained.
- ✗
Restart the computer and boot into Safe Mode.
Why it's wrong here
Safe Mode still loads the compromised operating system and leaves the encrypted files and network channel intact, so the malware can continue encrypting or exfiltrating. It is tempting because Safe Mode is a familiar troubleshooting step, and it would be correct for isolating a faulty driver rather than containing active ransomware.
Go deeper
Related to this question
Learn chapter
macOS Time Machine Backup
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.