220-1102 Security Practice Question
A user calls the help desk stating that a pop-up message has appeared claiming all files on the computer have been encrypted and that a payment is required to unlock them. The user admits to opening an email attachment from an unknown sender earlier. What is the FIRST action the technician should take?
⚠ Common exam trap
220-1102 often tests the order of operations in malware incidents. Candidates might jump to scanning or restoring backups without first containing the threat, which can lead to further spread or re-infection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the computer from the network immediately
The first action should be to disconnect the computer from the network immediately to prevent the ransomware from spreading to other systems or communicating with command-and-control servers. This containment step is critical before any other remediation, such as scanning or restoring files, as it limits the damage and preserves evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disconnect the computer from the network immediately
Why this is correct
Immediately disconnecting the workstation from the network is the correct first response because ransomware actively seeks out and encrypts mapped drives, network shares, and other reachable systems through SMB and other protocols. Isolation halts lateral movement, preventing the encryption from spreading to servers or adjacent endpoints linked to the same logical or physical network. This containment step also preserves the integrity of forensic evidence by freezing the current state of infection before additional processes alter the filesystem. Without network isolation, every minute of continued connectivity increases the scope of data loss and the number of systems requiring recovery.
- ✗
Run a full antivirus scan
Why it's wrong here
Running a full antivirus scan is an insufficient first response because antivirus tools are primarily designed to detect known malware signatures and may not identify a new or polymorphic ransomware variant, nor can they decrypt files that have already been encrypted. Executing a scan on an actively compromised host also consumes CPU and disk I/O, potentially allowing ransomware to continue encrypting files while the scan runs, and malware can sometimes evade in-memory detection or disable the AV process. The immediate priority must be containment by severing network access, not scanning; only after the system is isolated should malware identification and removal be attempted. Antivirus can help eradicate the infection but cannot remedy the core damage of file encryption, so it is a secondary step.
- ✗
Pay the ransom to recover the files
Why it's wrong here
Paying the ransom to recover the files is unequivocally the wrong action because there is no contractual or technical guarantee that attackers will provide a working decryption key after payment, and many victims report receiving no decryption tool or a flawed one. Funds transfer also finances criminal operations and encourages repeat targeting, as cybercriminals often maintain lists of victims who have paid and will attack them again. Law enforcement agencies, including the FBI and CISA, explicitly advise against paying ransoms because it does not ensure data recovery and may expose the victim to further extortion. Even if payment appears to be the fastest path, the only reliable response is containment, backed by validated offline backups.
- ✗
Restore files from a recent backup
Why it's wrong here
Restoring files from a recent backup is a necessary recovery step but it is performed only after the system has been disconnected from the network and cleaned of the ransomware infection. If you restore while the machine is still connected, the original ransomware executable can re-encrypt the restored files instantly, and the infection can also propagate to backup storage if that backup is mapped as a network share or is otherwise accessible. Moreover, the backup itself may be compromised if it was continuously connected and had already been encrypted during the attack, rendering it useless. The correct sequence is isolate first, then validate the backup's integrity and ensure the malware is fully removed, and only then perform the restore as part of a controlled recovery plan.
Go deeper
Related to this question
Learn chapter
Malware Classification: Virus, Worm, Ransomware, Rootkit
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.