Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user receives an email that appears to be from a regular vendor, containing an invoice attachment. The user opens the attachment, but nothing seems to happen. The user reports the incident to the help desk. The technician confirms the email is a phishing attempt and that the attachment likely contained malware. No immediate signs of infection are visible. According to incident response best practices, what should the technician do FIRST?

⚠ Common exam trap

Watch out — candidates often assume antivirus scanning is the immediate corrective action, but CompTIA emphasizes containment before eradication to prevent malware from spreading or communicating with its C2 infrastructure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disconnect the workstation from the network immediately

Disconnecting the workstation from the network is the first priority in incident response to contain the potential malware and prevent it from communicating with a command-and-control server, spreading laterally, or exfiltrating data. Even with no visible signs of infection, the malware could be establishing persistence or performing reconnaissance. This aligns with the 'Containment' phase of the NIST SP 800-61 incident response lifecycle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a full antivirus scan on the workstation

    Why it's wrong here

    Running a full antivirus scan is a reactive measure that does nothing to stop an active threat from spreading. During the scan, the infected workstation remains on the network, allowing any active malware to contact command-and-control servers or pivot to other hosts. Antivirus also relies on signatures, which may not flag novel or obfuscated payloads, so a negative result does not prove the system is safe. Containment through disconnection must always precede scanning or any other remediation step.

  • ✓

    Disconnect the workstation from the network immediately

    Why this is correct

    Disconnecting the workstation from the network immediately is the correct first step because it contains the incident at the host. Pulling the network cable or disabling the wireless adapter stops any active malware from communicating with external command-and-control infrastructure and prevents lateral movement to other systems. This isolation also preserves volatile evidence in memory and on disk, which can be compromised if the host remains connected. Time is critical, so this action takes precedence over scanning, forensics, or remediation.

  • ✗

    Delete the email from the user's mailbox

    Why it's wrong here

    Deleting the email from the user's mailbox is ineffective because the malicious attachment has likely already been opened and executed on the endpoint. The email is merely the delivery vector; the actual threat now resides in the workstation's memory or file system. Furthermore, removing the email destroys potential forensic evidence, such as header information, links, or payload hashes, that could be used for threat intelligence and attribution. The correct response is to isolate the host before addressing the email artifact.

  • ✗

    Perform a system restore to a point before the attachment was opened

    Why it's wrong here

    Performing a system restore to a point before the attachment was opened is not the immediate first step, and it may not even be effective against the infection. Many malware variants install persistence mechanisms outside the locations that system restore reverts, such as in the boot sector, firmware, or scheduled tasks in other folders. Additionally, malware can inject into restore points themselves, so rolling back could simply restore an already-compromised state. Only after the system is isolated and scanned should a restore be considered as part of a broader recovery plan.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.