Courseiva
mediumMultiple ChoiceObjective-mapped

220-1102 Practice Question: That their computer is displaying a message…

A user reports that their computer is displaying a message claiming their files are encrypted and they must pay 0.5 Bitcoin to a specific address to regain access. The user cannot open any documents or photos. What is the first step the technician should take to respond to this incident?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disconnect the computer from the network.

The first step in a ransomware incident is to isolate the infected system from the network to prevent the malware from spreading to other devices. Attempting to decrypt without tools or paying the ransom are not recommended initial actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Pay the ransom to recover the files immediately.

    Why it's wrong here

    Paying the ransom is strongly discouraged as it directly funds criminal enterprises and provides no guarantee that the decryption key will be provided or will even work correctly. Engaging with cybercriminals also signals that your organization is a willing target, potentially leading to future attacks. This action does not resolve the underlying security vulnerability that allowed the ransomware in the first place, leaving the system susceptible.

  • Disconnect the computer from the network.

    Why this is correct

    Immediately disconnecting the infected computer from all network connections, including both wired Ethernet and Wi-Fi, is the most critical initial step in ransomware containment. This action prevents the malware from propagating to other network shares, connected devices, or servers, thereby limiting the scope of the attack. It also stops any potential data exfiltration attempts, safeguarding additional organizational assets and preventing further compromise.

  • Run a full antivirus scan to remove the malware.

    Why it's wrong here

    Running a full antivirus scan, while part of the eradication phase, is not the immediate priority when ransomware is detected. The primary damage, file encryption, has already occurred, and performing a scan without prior network isolation risks the ransomware spreading further across the network before it can be fully removed. Furthermore, antivirus software typically removes the malware but does not possess the capability to decrypt files without the original key, which is held by the attacker.

  • Reboot the computer into Safe Mode.

    Why it's wrong here

    Rebooting into Safe Mode can be a useful step for malware removal by loading only essential system components, potentially preventing the ransomware's full execution and making it easier to clean. However, it does not address the critical immediate threat of network propagation, as the system might still attempt network connections during the reboot process or upon entering Safe Mode. The priority is to contain the threat by isolating the system from the network *before* attempting any diagnostic or removal procedures that involve rebooting.

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.