220-1102 Security Practice Question
A workstation in a corporate environment has been infected with ransomware. The user reports that files are being encrypted and a ransom note is displayed. The technician arrives at the workstation. Which of the following is the FIRST action the technician should take to minimize further damage?
⚠ Common exam trap
Candidates often confuse 'immediate containment' with 'immediate eradication,' choosing to run an antivirus scan (Option A) or power off (Option C) instead of isolating the system from the network first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the network cable from the workstation.
Disconnecting the network cable (Option B) is the first action because it immediately stops the ransomware from communicating with its command-and-control (C2) server, preventing further encryption of network shares, mapped drives, or other systems. It also blocks the ransomware from exfiltrating data or receiving additional payloads, containing the incident to the single workstation without risking data loss from an abrupt power-off.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on the workstation.
Why it's wrong here
Running a full antivirus scan is a detection-centric reaction that assumes the ransomware signature is already known, but active encryption processes are already in memory and will continue modifying files while the scanner reads the disk. This simultaneous I/O contention not only slows the scan but can also trigger the malware to accelerate its encryption routine, and the heavy filesystem access alters access timestamps and other metadata essential for forensic analysis. Containment by severing the network connection must occur before any scanning, because the scan cannot undo ongoing encryption and may give the ransomware additional time to spread via mapped drives.
- ✓
Disconnect the network cable from the workstation.
Why this is correct
Disconnecting the network cable immediately removes the workstation from the Layer 2 broadcast domain, terminating all active SMB/CIFS sessions to corporate file shares and blocking outbound connections to command-and-control infrastructure. This isolation-first action halts lateral movement across the network and prevents the ransomware from exfiltrating data or receiving decryption instructions, while preserving the live state in RAM for later memory forensics. Unlike powering off, this leaves the local processes intact so investigators can capture the ransomware binary and encryption artifacts, making it the correct initial step in incident containment.
- ✗
Power off the workstation immediately.
Why it's wrong here
Powering off preserves the encrypted state but may allow the ransomware to have completed encryption on the local drive. More importantly, the network connection would still be active if not disconnected, so disconnecting the cable is a better first step.
- ✗
Take a screenshot of the ransom note for documentation.
Why it's wrong here
Taking a screenshot of the ransom note is a documentation task that belongs to the later evidence-preservation phase, after the threat has been contained and the system is safely isolated. While the network cable remains connected, each moment spent capturing the screen gives the ransomware additional time to encrypt network shares, delete Volume Shadow Copies, and spread to adjacent hosts. The ransom note's details, such as the cryptocurrency wallet address and contact email, can be recorded later from disk images or the encrypted system itself, so deferring this step does not lose critical information but does save the network from further damage.
Go deeper
Related to this question
Learn chapter
Data Destruction and Disposal
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.