Courseiva
easyMultiple Choice

220-1102 Practice Question: A user calls the help desk because their…

A user calls the help desk because their workstation is running very slowly and they notice unusual network activity. You suspect ransomware. What should you do first to contain the threat?

⚠ Common exam trap

CompTIA A+ emphasizes that containment (isolation) must precede remediation (scanning, backup, or boot changes) in incident response. The trap here is that candidates mistakenly choose a reactive remediation step like running a scan or backing up files, which can worsen the spread or data loss.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disconnect the workstation from the network immediately.

Disconnecting the workstation from the network immediately is the correct first step because ransomware often uses network propagation mechanisms (e.g., SMB, RDP) to encrypt shared drives and spread to other systems. By isolating the machine at the physical or logical layer, you prevent lateral movement and further encryption of network resources, which is the primary containment priority in a suspected ransomware incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a full antivirus scan on the affected workstation.

    Why it's wrong here

    Scanning lets the malware keep running and encrypting during the scan, and many strains disable or evade the installed antivirus. It is tempting because a scan is the standard response to suspected infection, and it would be correct once the host is already isolated from the network and storage.

  • ✓

    Disconnect the workstation from the network immediately.

    Why this is correct

    Severing the network connection halts command-and-control traffic and lateral movement or encryption of shared resources, containing ransomware before eradication. It is the immediate first action; powering off or remediating in place risks further spread and destroys volatile evidence.

  • ✗

    Back up all files to an external drive before taking action.

    Why it's wrong here

    Copying files to external media spreads the infection and preserves encrypted data rather than stopping the encryption process. It is tempting because preserving evidence and data feels prudent, and backing up would be correct before remediation once the machine is disconnected and the threat is contained.

  • ✗

    Restart the computer and boot into Safe Mode.

    Why it's wrong here

    Safe Mode still loads the compromised operating system and leaves the encrypted files and network channel intact, so the malware can continue encrypting or exfiltrating. It is tempting because Safe Mode is a familiar troubleshooting step, and it would be correct for isolating a faulty driver rather than containing active ransomware.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.