220-1102 Security Practice Question
A security administrator notices that a user's workstation is sending outbound traffic to a known malicious IP address at regular intervals. The user reports no unusual activity. The technician has already run a full antivirus scan with no detections. Which of the following should the technician do NEXT to investigate the persistent network connection?
⚠ Common exam trap
Watch out — candidates often confuse immediate containment (disabling the NIC) with the investigative step, failing to recognize that the question specifically asks for the next step to investigate the persistent connection, not to stop it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a network packet capture to analyze the traffic content.
A network packet capture (e.g., using Wireshark or tcpdump) allows the technician to inspect the actual payload and protocol headers of the outbound traffic. Since the antivirus scan found no malware, the connection may be using a legitimate process that has been hijacked or is beaconing to a C2 server. Analyzing the traffic content can reveal the destination port, application-layer data, and whether the communication is encrypted or contains command-and-control patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run a network packet capture to analyze the traffic content.
Why this is correct
Running a network packet capture with a tool such as Wireshark or tcpdump provides a detailed view of the actual data being transmitted, including packet payloads, protocol headers, and destination IP address responses. This allows you to identify whether the outbound traffic is command-and-control beaconing, data exfiltration, or an application acting abnormally, and it preserves volatile evidence in real time. As the best investigative step, packet capture gives you the ground truth needed to determine the nature of the communication and to guide subsequent containment or remediation.
- ✗
Disable the network adapter and disconnect the workstation from the network.
Why it's wrong here
Disabling the network adapter and physically disconnecting the workstation is a containment action, not an investigative step. While it halts the suspicious outbound traffic and may limit further compromise, it immediately terminates the active sessions, preventing you from observing the destination's responses, the beacon interval, or the full payload of ongoing exfiltration. It also introduces a risk that the malware may detect the sudden loss of connectivity and trigger anti-forensic behavior such as self-deletion, so it must be deferred until after evidence is captured unless the immediate threat outweighs the need for analysis.
- ✗
Reimage the workstation immediately.
Why it's wrong here
Reimaging the workstation immediately is a recovery action that destroys all forensic evidence, including malware binaries, persistence mechanisms, registry artifacts, and any remnants of the outbound communication captured in memory or temporary files. It is premature because it does not reveal how the compromise occurred or what data may have been stolen, leaving the root cause unaddressed and the network vulnerable to reinfection. Reimaging should only be performed after the threat is fully understood and after you have preserved forensic data through memory acquisition and disk imaging.
- ✗
Check the Windows Firewall logs for blocked connections.
Why it's wrong here
Checking the Windows Firewall logs is ineffective here because the outbound traffic to the malicious IP is succeeding and is therefore not being blocked. By default, Windows Defender Firewall logs only blocked connection attempts unless 'Log successful connections' is explicitly enabled, and even then the log would only contain metadata like source and destination IPs, ports, and timestamps—not the content of the communication. Since the traffic is allowed, the firewall log will likely show no record of it, making this option useless for investigating the active outbound connection.
Visual reference
Go deeper
Related to this question
Learn chapter
SOHO Network Security
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Packet capture
Packet capture is the process of intercepting and recording data packets traveling over a computer network for analysis.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.