220-1102 Operational Procedures Practice Question
A technician discovers that a user's workstation has been compromised. Logs indicate that sensitive data has been exfiltrated. According to incident response best practices, which action should the technician take FIRST?
⚠ Common exam trap
A common mix-up: candidates confuse the order of incident response steps, choosing to scan or rebuild first instead of containing the breach, which violates the fundamental 'contain before eradicate' principle tested in CompTIA 220-1102.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the workstation from the network
According to incident response best practices, the first priority is to contain the breach and prevent further data exfiltration. Disconnecting the workstation from the network immediately stops the attacker's ability to communicate with the compromised system, halting data transfer and preventing lateral movement. This aligns with the NIST SP 800-61 incident response framework, which emphasizes containment before eradication or recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disconnect the workstation from the network
Why this is correct
Disconnecting the workstation from the network is the immediate containment step that stops active data exfiltration, prevents lateral movement to other hosts, and preserves volatile evidence (e.g., live network connections or in-memory artifacts) for subsequent forensic analysis. It prioritizes limiting the blast radius over any reactive cleanup activity, which aligns with the first phase of incident response.
- ✗
Run a full antivirus scan
Why it's wrong here
Running a full antivirus scan on a live, compromised system can alert the attacker and trigger anti-forensic actions, while also modifying critical evidence by updating file access times, quarantining malicious files, or deleting artifacts before they can be captured. Advanced malware may be memory-resident or polymorphic, so a scan is unlikely to be conclusive. Incident response requires containment and evidence preservation first, not a scan that assumes the threat is static and file-based.
- ✗
Report the incident to law enforcement
Why it's wrong here
Reporting to law enforcement is a legal and organizational step that must follow the incident response policy, which typically requires containment and evidence preservation before any external communication. Early reporting without a preserved chain of custody or documented evidence can complicate legal proceedings, and it does not stop the attacker's continued access or lateral movement. The immediate on-scene action is to isolate the host; then, after proper evidence collection and per policy, law enforcement is notified.
- ✗
Rebuild the workstation
Why it's wrong here
Rebuilding the workstation is part of eradication and recovery, not the first response. Imaging the drive or wiping it would destroy volatile data, logs, and malware samples that are essential for determining the attack vector, scope, and attribution. Per best practice, you must preserve forensic evidence and conduct a proper investigation before rebuild, and even then only if policy deems the system untrusted or if the cost of forensic analysis outweighs the benefit.
Go deeper
Related to this question
Learn chapter
Windows User Accounts and Groups
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.