Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A technician discovers that a user's workstation is infected with ransomware. Following the incident response plan, the technician isolates the system from the network. What should the technician do NEXT?

⚠ Common exam trap

The trap here is that candidates often jump to the most drastic action (wiping the drive) without following the structured incident response process, which prioritizes containment and evidence preservation before eradication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify the infection vector

After isolating the infected workstation, the next step per incident response procedures is to identify the infection vector. This involves analyzing logs, file system artifacts, and network traffic to determine how the ransomware entered (e.g., phishing email, malicious download, or exploit). Understanding the vector is critical to prevent reinfection and to assess the scope of the incident before any remediation steps like wiping the drive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Wipe the hard drive and reinstall the operating system

    Why it's wrong here

    Wiping the hard drive and reinstalling the OS is an extreme, irreversible measure that destroys the digital evidence—such as event logs, file system metadata, and memory artifacts—needed to trace how the ransomware was introduced. Without identifying the vector, a fresh install remains vulnerable to the exact same entry point, allowing rapid re-infection. This action also needlessly risks data loss if a more controlled restoration from verified backups or a targeted remediation is feasible. In incident response, a full wipe is justified only after forensic preservation and a determination that the system cannot be safely cleaned.

  • ✓

    Identify the infection vector

    Why this is correct

    Identifying the infection vector is the first essential step in any ransomware incident response because it reveals the attacker's entry path—whether from a phishing attachment, compromised RDP credentials, or an unpatched vulnerability. This insight enables containment actions like blocking malicious domains, isolating affected segments, and disabling compromised accounts, while also informing the eradication and recovery phases. Without root-cause identification, you cannot prevent the threat from spreading to other hosts or recurring after cleanup. It is the technical foundation for every subsequent decision, including whether decryption or restoration is appropriate.

  • ✗

    Attempt to decrypt the files using available tools

    Why it's wrong here

    Attempting to decrypt files prematurely is risky because available decryption tools are variant-specific; using the wrong tool can corrupt data or fail entirely, and you often have no way to know the variant without first analyzing the ransomware payload. The immediate goal is to stop the spread and identify the vector, not to salvage data, since many modern ransomware families use strong encryption that is effectively unbreakable without the attacker's key. Even if a decryption tool existed, decryption alone leaves the original vulnerability open, so the infection vector would still need to be addressed. Therefore, decryption is a recovery-phase activity that should wait until the root cause is understood.

  • ✗

    Contact the user's manager to inform them of the incident

    Why it's wrong here

    Notifying the user's manager addresses organizational communication but does nothing to contain the ransomware or uncover how it entered the network, which are the immediate technical priorities. Incident response plans typically define a specific chain of escalation that includes security leadership and possibly legal or compliance teams, but the technical team must first isolate the system and collect forensic evidence. Management notification can happen in parallel without taking precedence over vector identification, and prematurely alarming stakeholders before the scope is known can hinder an efficient response. For a CompTIA A+ technician, the correct action is to focus on the technical steps that protect the environment and establish root cause.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.