mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: That their computer is displaying a message…
A user reports that their computer is displaying a message claiming their files are encrypted and they must pay 0.5 Bitcoin to a specific address to regain access. The user cannot open any documents or photos. What is the first step the technician should take to respond to this incident?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the computer from the network.
The first step in a ransomware incident is to isolate the infected system from the network to prevent the malware from spreading to other devices. Attempting to decrypt without tools or paying the ransom are not recommended initial actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pay the ransom to recover the files immediately.
Why it's wrong here
Paying the ransom is strongly discouraged as it directly funds criminal enterprises and provides no guarantee that the decryption key will be provided or will even work correctly. Engaging with cybercriminals also signals that your organization is a willing target, potentially leading to future attacks. This action does not resolve the underlying security vulnerability that allowed the ransomware in the first place, leaving the system susceptible.
- ✓
Disconnect the computer from the network.
Why this is correct
Immediately disconnecting the infected computer from all network connections, including both wired Ethernet and Wi-Fi, is the most critical initial step in ransomware containment. This action prevents the malware from propagating to other network shares, connected devices, or servers, thereby limiting the scope of the attack. It also stops any potential data exfiltration attempts, safeguarding additional organizational assets and preventing further compromise.
- ✗
Run a full antivirus scan to remove the malware.
Why it's wrong here
Running a full antivirus scan, while part of the eradication phase, is not the immediate priority when ransomware is detected. The primary damage, file encryption, has already occurred, and performing a scan without prior network isolation risks the ransomware spreading further across the network before it can be fully removed. Furthermore, antivirus software typically removes the malware but does not possess the capability to decrypt files without the original key, which is held by the attacker.
- ✗
Reboot the computer into Safe Mode.
Why it's wrong here
Rebooting into Safe Mode can be a useful step for malware removal by loading only essential system components, potentially preventing the ransomware's full execution and making it easier to clean. However, it does not address the critical immediate threat of network propagation, as the system might still attempt network connections during the reboot process or upon entering Safe Mode. The priority is to contain the threat by isolating the system from the network *before* attempting any diagnostic or removal procedures that involve rebooting.
Go deeper
Related to this question
Learn chapter
Windows Command Line Tools
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.