Courseiva
Operational Procedures →easyMultiple Choice

220-1102 Operational Procedures Practice Question

A user calls the help desk reporting that their workstation is displaying a full-screen message claiming all files are encrypted and demanding a payment in Bitcoin to unlock them. According to incident response best practices, what should the technician do FIRST?

⚠ Common exam trap

Many exam-takers choose to run an antivirus scan first, thinking it will remove the threat, but CompTIA emphasizes containment before remediation to prevent the incident from escalating.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disconnect the network cable from the workstation

The immediate priority in a ransomware incident is containment to prevent the malware from spreading to other systems on the network. Disconnecting the network cable (Option B) isolates the workstation, stopping any lateral movement or command-and-control communication. This aligns with the CompTIA incident response procedure: first identify and contain the threat before any remediation or reporting steps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reboot the workstation in Safe Mode

    Why it's wrong here

    Rebooting a system suspected of ransomware in Safe Mode is dangerous because modern ransomware often installs persistence mechanisms that execute during the boot cycle, even in a reduced driver environment. Many variants actively check for Safe Mode and will trigger encryption or delete-shadow-copy routines upon startup, while memory-resident payloads might detonate only after a reboot. The correct first step is to isolate the machine by cutting physical network connectivity, not to alter the system state and run the risk of accelerating the attack.

  • ✓

    Disconnect the network cable from the workstation

    Why this is correct

    Disconnecting the network cable is the immediate priority because it physically removes the workstation from both the local LAN and the internet, halting any active communication with command-and-control servers and preventing the ransomware from discovering and encrypting shared drives or spreading to adjacent hosts. This containment step does not rely on the OS, so the malware cannot intercept or spoof a software-based 'disconnect' command, and it simultaneously preserves volatile evidence such as running processes and memory while you prepare a more detailed forensic response.

  • ✗

    Run a full antivirus scan

    Why it's wrong here

    Running a full antivirus scan on a live, network-connected workstation during an ongoing ransomware event can be counterproductive because the scan reads thousands of files, which may inadvertently trigger the malware's encryption routine or cause it to replicate further across the network. Malicious executables may also be designed to evade or disable scan engines, and waiting for a scan to finish gives the ransomware more time to complete its payload and exfiltrate data. The correct sequence is to first contain the threat by isolating the system, then scan or reimage as part of the eradication phase, not before.

  • ✗

    Document the incident and report it to management

    Why it's wrong here

    Documenting the incident and reporting it to management before taking any technical action violates incident-response best practice because it delays containment while a live ransomware outbreak is actively spreading. Every minute of delay increases the chance that the encryption engine reaches more files, user shares, or backup locations, and the immediate action should be to preserve network integrity by disconnecting the machine. Once the system is isolated and the immediate threat is paused, the technician can then gather accurate details, document the timeline, and escalate to management for formal incident handling and compliance purposes.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.