Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A technician discovers that a workstation is infected with ransomware. The technician has isolated the computer from the network. What should the technician do NEXT according to incident response procedures?

⚠ Common exam trap

The trap here is that candidates often jump to immediate remediation (wiping or scanning) without recognizing that incident response requires formal reporting and escalation before any destructive or investigative actions are taken.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Report the incident to the manager or incident response team

According to incident response procedures, after isolating an infected system, the next step is to report the incident to the appropriate authority (manager or incident response team) to ensure proper documentation, escalation, and coordination of containment and eradication efforts. This aligns with the NIST SP 800-61 incident response lifecycle, where reporting triggers formal handling before any remediation actions like wiping or scanning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Wipe the hard drive and reinstall the operating system

    Why it's wrong here

    Performing a wipe and reinstall destroys transient and on-disk forensic artifacts—such as the ransomware binary, encryption logs, and the initial access vector—that are essential for determining how the infection occurred and what systems or data were compromised. The attack chain must be understood before any destructive recovery step, otherwise a reimaged host can be re-infected if the same vulnerability or credential remains exposed. In incident response, eradication and recovery are later phases that should only occur after reporting, containment, and evidence preservation.

  • ✓

    Report the incident to the manager or incident response team

    Why this is correct

    Reporting the incident to the manager or incident response team is the mandatory first step because it activates the formal incident response plan, triggers a coordinated containment effort, and establishes a documented chain of custody for all subsequent actions. It also ensures that appropriate stakeholders—such as legal, HR, or law enforcement—are notified when regulated data is involved, and it prevents an individual technician from taking unauthorized or harmful action that could compromise the investigation. This step is the foundation of NIST and CompTIA incident response procedures.

  • ✗

    Reset the user's password

    Why it's wrong here

    Resetting the user's password is a common containment measure, but it is not the immediate next step because it does nothing to halt ransomware that has already escalated privileges, exfiltrated data, or spread via cached credentials or service accounts. Additionally, performing a password reset before reporting can interfere with IR team forensics, because it changes the state of the environment and may lock out accounts that the analysts need for tracing the attacker's lateral movement. The reset should be executed only after the incident is reported and the IR team has authorized a containment plan.

  • ✗

    Scan other computers on the network for the same strain

    Why it's wrong here

    Scanning the network for additional infections is a worthwhile reconnaissance activity, but it must not be done before the incident is reported because uncoordinated scanning can trigger endpoint alarms, alter log evidence, or overload the network while containment is still pending. The incident response team needs to determine the ransomware strain's propagation mechanism—such as SMB shares, PowerShell, or scheduled tasks—before scanning, so the scans target the right IOCs and avoid spreading the malware. Early scanning also risks missing lateral movement that relies on living-off-the-land techniques.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.