Courseiva
hardMultiple ChoiceObjective-mapped

220-1102 Practice Question: That their computer is infected with a virus that…

A user reports that their computer is infected with a virus that has encrypted all their personal files and left a text file with instructions to pay a ransom. The technician has verified the infection is ransomware. The company has a backup policy. What is the best course of action to recover the data?

⚠ Common exam trap

CompTIA often tests the misconception that paying the ransom or using a decryption tool is a viable recovery method, when the correct answer is always to restore from a known-good backup after malware removal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Restore the files from a recent backup after removing the malware.

The company has a backup policy, meaning a recent, clean backup should exist. Restoring from backup after removing the ransomware ensures data recovery without paying criminals or relying on unreliable decryption tools. This aligns with best practices for ransomware incidents: isolate, remove, then restore from verified backups.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Pay the ransom and hope the decryption key is provided.

    Why it's wrong here

    Paying the ransom is strongly discouraged by cybersecurity experts and law enforcement agencies. There is no guarantee that the attackers will provide a working decryption key, and even if they do, the system may still contain residual malware or vulnerabilities. Furthermore, paying incentivizes cybercriminals to continue their illicit activities, making future attacks more likely for other victims and potentially funding other criminal enterprises.

  • Use a ransomware decryption tool from a reputable source.

    Why it's wrong here

    While reputable security vendors sometimes develop decryption tools for specific ransomware variants, these tools are often released only after a significant period of analysis and are not available for every new or sophisticated strain. Many ransomware families use strong, unique encryption keys per victim, making universal decryption tools ineffective. Relying solely on such a tool is often a futile effort, as the necessary key or algorithm might not be publicly available or effective against the specific variant encountered.

  • Restore the files from a recent backup after removing the malware.

    Why this is correct

    Restoring files from a recent, clean backup is the most effective and recommended method for recovering from a ransomware attack without engaging with the attackers. After ensuring the malware has been completely removed from the infected system, a technician can confidently overwrite the encrypted files with unencrypted versions from a verified backup. This approach bypasses the need for decryption, guarantees data integrity (assuming the backup is sound), and avoids supporting criminal enterprises.

  • Reinstall the operating system and hope the files become accessible.

    Why it's wrong here

    Reinstalling the operating system will remove the ransomware program itself and restore system functionality, but it will not decrypt any files that were already encrypted by the malware. The encrypted data files remain in their unreadable state on the storage drive, regardless of the OS reinstallation. This action only addresses the operating system's integrity and removes the active threat, not the data's encryption status, leaving user data inaccessible.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.