220-1102 Operational Procedures Practice Question
A user calls the help desk reporting that their workstation is displaying a full-screen message claiming all files are encrypted and demanding a payment in Bitcoin to unlock them. According to incident response best practices, what should the technician do FIRST?
⚠ Common exam trap
Many exam-takers choose to run an antivirus scan first, thinking it will remove the threat, but CompTIA emphasizes containment before remediation to prevent the incident from escalating.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the network cable from the workstation
The immediate priority in a ransomware incident is containment to prevent the malware from spreading to other systems on the network. Disconnecting the network cable (Option B) isolates the workstation, stopping any lateral movement or command-and-control communication. This aligns with the CompTIA incident response procedure: first identify and contain the threat before any remediation or reporting steps.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reboot the workstation in Safe Mode
Why it's wrong here
Rebooting a system suspected of ransomware in Safe Mode is dangerous because modern ransomware often installs persistence mechanisms that execute during the boot cycle, even in a reduced driver environment. Many variants actively check for Safe Mode and will trigger encryption or delete-shadow-copy routines upon startup, while memory-resident payloads might detonate only after a reboot. The correct first step is to isolate the machine by cutting physical network connectivity, not to alter the system state and run the risk of accelerating the attack.
- ✓
Disconnect the network cable from the workstation
Why this is correct
Disconnecting the network cable is the immediate priority because it physically removes the workstation from both the local LAN and the internet, halting any active communication with command-and-control servers and preventing the ransomware from discovering and encrypting shared drives or spreading to adjacent hosts. This containment step does not rely on the OS, so the malware cannot intercept or spoof a software-based 'disconnect' command, and it simultaneously preserves volatile evidence such as running processes and memory while you prepare a more detailed forensic response.
- ✗
Run a full antivirus scan
Why it's wrong here
Running a full antivirus scan on a live, network-connected workstation during an ongoing ransomware event can be counterproductive because the scan reads thousands of files, which may inadvertently trigger the malware's encryption routine or cause it to replicate further across the network. Malicious executables may also be designed to evade or disable scan engines, and waiting for a scan to finish gives the ransomware more time to complete its payload and exfiltrate data. The correct sequence is to first contain the threat by isolating the system, then scan or reimage as part of the eradication phase, not before.
- ✗
Document the incident and report it to management
Why it's wrong here
Documenting the incident and reporting it to management before taking any technical action violates incident-response best practice because it delays containment while a live ransomware outbreak is actively spreading. Every minute of delay increases the chance that the encryption engine reaches more files, user shares, or backup locations, and the immediate action should be to preserve network integrity by disconnecting the machine. Once the system is isolated and the immediate threat is paused, the technician can then gather accurate details, document the timeline, and escalate to management for formal incident handling and compliance purposes.
Go deeper
Related to this question
Learn chapter
Network Topology Documentation
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.