Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A technician discovers that a user's workstation is infected with a Trojan that is logging keystrokes and capturing login credentials. The technician has already disconnected the computer from the network. According to standard incident response procedures, what should the technician do NEXT?

⚠ Common exam trap

Many candidates confuse the urgency of reporting (Option B) or the forensic preservation step (Option C) with the logical next step, but CompTIA expects you to follow the structured incident response order where analysis of scope and impact comes immediately after containment, not before.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analyze the scope and impact of the infection

After disconnecting the infected workstation from the network, the next step in standard incident response (NIST SP 800-61) is to analyze the scope and impact of the infection. This involves determining what data was compromised (e.g., keystroke logs, captured credentials), how the Trojan entered the system, and whether other systems are affected. Jumping to reporting, imaging, or reinstallation without this analysis can lead to incomplete remediation and failure to contain the incident properly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Analyze the scope and impact of the infection

    Why this is correct

    Analyzing the scope and impact is the correct next step after containing the trojan. This determines which files, credentials, or sensitive data the keylogger may have captured, how the infection entered the system, and whether it spread to other hosts. The results drive eradication, recovery, and future prevention, and they also produce the facts needed for any legal or management reporting.

  • ✗

    Report the incident to management immediately

    Why it's wrong here

    Reporting the incident to management immediately is premature at this stage. Management should receive a complete, accurate impact assessment, not an initial alarm without verified data. Skipping analysis can lead to understating or overstating the breach, complicating regulatory notifications, and undermining the trustworthiness of the incident response report.

  • ✗

    Create a forensic image of the hard drive

    Why it's wrong here

    Creating a forensic image is an evidence preservation step that should occur before or during containment, not after. Once containment actions are performed, memory, filesystem metadata, and volatile data may be altered, reducing the integrity of the evidentiary copy. If you need the image for prosecution or root-cause analysis, it must be acquired early using write-blockers and proper chain-of-custody procedures.

  • ✗

    Reinstall the operating system

    Why it's wrong here

    Reinstalling the operating system too early is a common remediation mistake. Without first analyzing the infection's scope, you may remove the trojan but fail to identify the initial attack vector, exfiltrated data, or backdoors left by the attacker. Reimaging can also destroy forensic evidence and could result in reinfection if the root cause is not understood and addressed.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.