Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user calls the help desk, very agitated, stating that a full-screen popup on their workstation says 'SYSTEM LOCKED' and demands $500 in Bitcoin to unlock. The user cannot perform any other actions because the popup covers the screen. The technician remotely views the screen and confirms it is a ransomware warning. The technician has already instructed the user to disconnect the network cable. According to best practices, what should the technician do NEXT?

⚠ Common exam trap

The trap here is that candidates often jump to the most drastic recovery action (reformatting) without recognizing that proper incident response requires documentation and evidence preservation first, as per CompTIA's emphasis on the order of operations in the incident response process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the incident, capture a screenshot, and begin the incident response process

After isolating the infected system by disconnecting the network cable, the next best practice step is to document the incident (including capturing a screenshot for forensic evidence) and initiate the formal incident response process. This aligns with the NIST SP 800-61 incident response framework, which emphasizes containment, evidence preservation, and escalation before any remediation or recovery actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately reformat the hard drive and reinstall the operating system

    Why it's wrong here

    Immediately reformatting the hard drive and reinstalling the OS is an irreversible action that destroys volatile and non-volatile forensic evidence, including the ransomware binary, persistence mechanisms, and any remnants of the encryption process that could aid in decrypting files or identifying the threat actor. Proper incident response dictates preserving the system state first, documenting chain of custody, and performing forensic imaging before any eradication steps. Reformatting should only be considered after the incident has been fully analyzed and recovery strategies have been exhausted, not as a reflexive response.

  • ✗

    Pay the ransom to restore access to the files

    Why it's wrong here

    Paying the ransom does not guarantee file recovery because the attacker may not possess a working decryption key, may have already corrupted the encrypted data, or may simply extort more money; it also directly finances the criminal infrastructure used to target the organization. Furthermore, many organizations have legal or regulatory policies that prohibit ransom payments, and making such a payment without involving law enforcement can hinder incident response and damage the organization's reputation. Risk mitigation should instead focus on restoring from verified backups after isolating the infection and preserving forensic evidence.

  • ✓

    Document the incident, capture a screenshot, and begin the incident response process

    Why this is correct

    This aligns with incident response best practices. Documenting and preserving evidence (including a screenshot) is critical for internal investigations and potential legal action. The incident response process will guide further steps such as containment, eradication, and recovery.

  • ✗

    Run a full antivirus scan to remove the ransomware

    Why it's wrong here

    Running a scan on a live, compromised system may alter evidence and is unlikely to decrypt already-encrypted files. Antivirus removal should be part of the eradication step later in the incident response process, not the immediate next step.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.