220-1102 Security Practice Question
A user receives an email that appears to be from a regular vendor, containing an invoice attachment. The user opens the attachment, but nothing seems to happen. The user reports the incident to the help desk. The technician confirms the email is a phishing attempt and that the attachment likely contained malware. No immediate signs of infection are visible. According to incident response best practices, what should the technician do FIRST?
⚠ Common exam trap
Watch out — candidates often assume antivirus scanning is the immediate corrective action, but CompTIA emphasizes containment before eradication to prevent malware from spreading or communicating with its C2 infrastructure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the workstation from the network immediately
Disconnecting the workstation from the network is the first priority in incident response to contain the potential malware and prevent it from communicating with a command-and-control server, spreading laterally, or exfiltrating data. Even with no visible signs of infection, the malware could be establishing persistence or performing reconnaissance. This aligns with the 'Containment' phase of the NIST SP 800-61 incident response lifecycle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on the workstation
Why it's wrong here
Running a full antivirus scan is a reactive measure that does nothing to stop an active threat from spreading. During the scan, the infected workstation remains on the network, allowing any active malware to contact command-and-control servers or pivot to other hosts. Antivirus also relies on signatures, which may not flag novel or obfuscated payloads, so a negative result does not prove the system is safe. Containment through disconnection must always precede scanning or any other remediation step.
- ✓
Disconnect the workstation from the network immediately
Why this is correct
Disconnecting the workstation from the network immediately is the correct first step because it contains the incident at the host. Pulling the network cable or disabling the wireless adapter stops any active malware from communicating with external command-and-control infrastructure and prevents lateral movement to other systems. This isolation also preserves volatile evidence in memory and on disk, which can be compromised if the host remains connected. Time is critical, so this action takes precedence over scanning, forensics, or remediation.
- ✗
Delete the email from the user's mailbox
Why it's wrong here
Deleting the email from the user's mailbox is ineffective because the malicious attachment has likely already been opened and executed on the endpoint. The email is merely the delivery vector; the actual threat now resides in the workstation's memory or file system. Furthermore, removing the email destroys potential forensic evidence, such as header information, links, or payload hashes, that could be used for threat intelligence and attribution. The correct response is to isolate the host before addressing the email artifact.
- ✗
Perform a system restore to a point before the attachment was opened
Why it's wrong here
Performing a system restore to a point before the attachment was opened is not the immediate first step, and it may not even be effective against the infection. Many malware variants install persistence mechanisms outside the locations that system restore reverts, such as in the boot sector, firmware, or scheduled tasks in other folders. Additionally, malware can inject into restore points themselves, so rolling back could simply restore an already-compromised state. Only after the system is isolated and scanned should a restore be considered as part of a broader recovery plan.
Go deeper
Related to this question
Learn chapter
Malware Types and Removal
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.