220-1102 Security Practice Question
A user calls the help desk, very agitated, stating that a full-screen popup on their workstation says 'SYSTEM LOCKED' and demands $500 in Bitcoin to unlock. The user cannot perform any other actions because the popup covers the screen. The technician remotely views the screen and confirms it is a ransomware warning. The technician has already instructed the user to disconnect the network cable. According to best practices, what should the technician do NEXT?
⚠ Common exam trap
The trap here is that candidates often jump to the most drastic recovery action (reformatting) without recognizing that proper incident response requires documentation and evidence preservation first, as per CompTIA's emphasis on the order of operations in the incident response process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the incident, capture a screenshot, and begin the incident response process
After isolating the infected system by disconnecting the network cable, the next best practice step is to document the incident (including capturing a screenshot for forensic evidence) and initiate the formal incident response process. This aligns with the NIST SP 800-61 incident response framework, which emphasizes containment, evidence preservation, and escalation before any remediation or recovery actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately reformat the hard drive and reinstall the operating system
Why it's wrong here
Immediately reformatting the hard drive and reinstalling the OS is an irreversible action that destroys volatile and non-volatile forensic evidence, including the ransomware binary, persistence mechanisms, and any remnants of the encryption process that could aid in decrypting files or identifying the threat actor. Proper incident response dictates preserving the system state first, documenting chain of custody, and performing forensic imaging before any eradication steps. Reformatting should only be considered after the incident has been fully analyzed and recovery strategies have been exhausted, not as a reflexive response.
- ✗
Pay the ransom to restore access to the files
Why it's wrong here
Paying the ransom does not guarantee file recovery because the attacker may not possess a working decryption key, may have already corrupted the encrypted data, or may simply extort more money; it also directly finances the criminal infrastructure used to target the organization. Furthermore, many organizations have legal or regulatory policies that prohibit ransom payments, and making such a payment without involving law enforcement can hinder incident response and damage the organization's reputation. Risk mitigation should instead focus on restoring from verified backups after isolating the infection and preserving forensic evidence.
- ✓
Document the incident, capture a screenshot, and begin the incident response process
Why this is correct
This aligns with incident response best practices. Documenting and preserving evidence (including a screenshot) is critical for internal investigations and potential legal action. The incident response process will guide further steps such as containment, eradication, and recovery.
- ✗
Run a full antivirus scan to remove the ransomware
Why it's wrong here
Running a scan on a live, compromised system may alter evidence and is unlikely to decrypt already-encrypted files. Antivirus removal should be part of the eradication step later in the incident response process, not the immediate next step.
Go deeper
Related to this question
Learn chapter
Malware Classification: Virus, Worm, Ransomware, Rootkit
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.