220-1102 Security Practice Question
A technician discovers that a user's workstation is infected with a Trojan that is logging keystrokes and capturing login credentials. The technician has already disconnected the computer from the network. According to standard incident response procedures, what should the technician do NEXT?
⚠ Common exam trap
Many candidates confuse the urgency of reporting (Option B) or the forensic preservation step (Option C) with the logical next step, but CompTIA expects you to follow the structured incident response order where analysis of scope and impact comes immediately after containment, not before.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyze the scope and impact of the infection
After disconnecting the infected workstation from the network, the next step in standard incident response (NIST SP 800-61) is to analyze the scope and impact of the infection. This involves determining what data was compromised (e.g., keystroke logs, captured credentials), how the Trojan entered the system, and whether other systems are affected. Jumping to reporting, imaging, or reinstallation without this analysis can lead to incomplete remediation and failure to contain the incident properly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Analyze the scope and impact of the infection
Why this is correct
Analyzing the scope and impact is the correct next step after containing the trojan. This determines which files, credentials, or sensitive data the keylogger may have captured, how the infection entered the system, and whether it spread to other hosts. The results drive eradication, recovery, and future prevention, and they also produce the facts needed for any legal or management reporting.
- ✗
Report the incident to management immediately
Why it's wrong here
Reporting the incident to management immediately is premature at this stage. Management should receive a complete, accurate impact assessment, not an initial alarm without verified data. Skipping analysis can lead to understating or overstating the breach, complicating regulatory notifications, and undermining the trustworthiness of the incident response report.
- ✗
Create a forensic image of the hard drive
Why it's wrong here
Creating a forensic image is an evidence preservation step that should occur before or during containment, not after. Once containment actions are performed, memory, filesystem metadata, and volatile data may be altered, reducing the integrity of the evidentiary copy. If you need the image for prosecution or root-cause analysis, it must be acquired early using write-blockers and proper chain-of-custody procedures.
- ✗
Reinstall the operating system
Why it's wrong here
Reinstalling the operating system too early is a common remediation mistake. Without first analyzing the infection's scope, you may remove the trojan but fail to identify the initial attack vector, exfiltrated data, or backdoors left by the attacker. Reimaging can also destroy forensic evidence and could result in reinfection if the root cause is not understood and addressed.
Go deeper
Related to this question
Learn chapter
SOHO Network Security
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Trojan
A Trojan is a type of malware that disguises itself as a legitimate file or program to trick users into installing it, then performs harmful actions without the user's knowledge.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.