220-1102 Security Practice Question
A technician discovers that a user's workstation is infected with ransomware. Following the incident response plan, the technician isolates the system from the network. What should the technician do NEXT?
⚠ Common exam trap
The trap here is that candidates often jump to the most drastic action (wiping the drive) without following the structured incident response process, which prioritizes containment and evidence preservation before eradication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify the infection vector
After isolating the infected workstation, the next step per incident response procedures is to identify the infection vector. This involves analyzing logs, file system artifacts, and network traffic to determine how the ransomware entered (e.g., phishing email, malicious download, or exploit). Understanding the vector is critical to prevent reinfection and to assess the scope of the incident before any remediation steps like wiping the drive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wipe the hard drive and reinstall the operating system
Why it's wrong here
Wiping the hard drive and reinstalling the OS is an extreme, irreversible measure that destroys the digital evidence—such as event logs, file system metadata, and memory artifacts—needed to trace how the ransomware was introduced. Without identifying the vector, a fresh install remains vulnerable to the exact same entry point, allowing rapid re-infection. This action also needlessly risks data loss if a more controlled restoration from verified backups or a targeted remediation is feasible. In incident response, a full wipe is justified only after forensic preservation and a determination that the system cannot be safely cleaned.
- ✓
Identify the infection vector
Why this is correct
Identifying the infection vector is the first essential step in any ransomware incident response because it reveals the attacker's entry path—whether from a phishing attachment, compromised RDP credentials, or an unpatched vulnerability. This insight enables containment actions like blocking malicious domains, isolating affected segments, and disabling compromised accounts, while also informing the eradication and recovery phases. Without root-cause identification, you cannot prevent the threat from spreading to other hosts or recurring after cleanup. It is the technical foundation for every subsequent decision, including whether decryption or restoration is appropriate.
- ✗
Attempt to decrypt the files using available tools
Why it's wrong here
Attempting to decrypt files prematurely is risky because available decryption tools are variant-specific; using the wrong tool can corrupt data or fail entirely, and you often have no way to know the variant without first analyzing the ransomware payload. The immediate goal is to stop the spread and identify the vector, not to salvage data, since many modern ransomware families use strong encryption that is effectively unbreakable without the attacker's key. Even if a decryption tool existed, decryption alone leaves the original vulnerability open, so the infection vector would still need to be addressed. Therefore, decryption is a recovery-phase activity that should wait until the root cause is understood.
- ✗
Contact the user's manager to inform them of the incident
Why it's wrong here
Notifying the user's manager addresses organizational communication but does nothing to contain the ransomware or uncover how it entered the network, which are the immediate technical priorities. Incident response plans typically define a specific chain of escalation that includes security leadership and possibly legal or compliance teams, but the technical team must first isolate the system and collect forensic evidence. Management notification can happen in parallel without taking precedence over vector identification, and prematurely alarming stakeholders before the scope is known can hinder an efficient response. For a CompTIA A+ technician, the correct action is to focus on the technical steps that protect the environment and establish root cause.
Go deeper
Related to this question
Learn chapter
Incident Response for A+
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
New Technology File System
New Technology File System (NTFS) is a modern file system developed by Microsoft that controls how data is stored, organized, and accessed on Windows-based hard drives and other storage devices.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.