220-1102 Operational Procedures Practice Question
A technician is creating a checklist for responding to a ransomware incident. According to best practices, which step should be performed FIRST after the ransomware is detected?
⚠ Common exam trap
Test-takers frequently think identifying the ransomware strain (Option A) is the logical first step for choosing a decryption tool, but CompTIA emphasizes containment before investigation to prevent further damage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the infected system from the network
The first priority when ransomware is detected is to contain the infection and prevent it from spreading to other systems on the network. Disconnecting the infected system from the network (Option B) immediately isolates the threat, stopping the ransomware from encrypting network shares, communicating with command-and-control servers, or propagating laterally. This containment step is critical before any analysis or recovery actions are taken.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Identify the ransomware strain
Why it's wrong here
Performing research to identify the ransomware strain (e.g., by hashing the binary, analyzing the ransom note, or querying C2 indicators) is useful for determining whether a public decryptor exists and for threat intelligence sharing. However, this analysis should be deferred until after the infected host is isolated, because active analysis on a live network connection allows the ransomware to continue encrypting mapped drives, escalating privileges, and communicating with its command-and-control server. In the incident response workflow, containment (like network disconnection) must precede forensics and threat identification to limit blast radius.
- ✓
Disconnect the infected system from the network
Why this is correct
Disconnecting the infected system from the network is the immediate containment action that severs the ransomware's command-and-control channel, stopping the encryption key exchange and halting lateral movement to adjacent hosts. This includes unplugging Ethernet, disabling Wi-Fi, and optionally blocking outbound traffic at the switch/firewall level to preserve evidence while preventing communication. According to standard IR playbooks, isolation is the top priority after detection, because every minute on the network allows the ransomware to propagate and encrypt more data.
- ✗
Restore files from backup
Why it's wrong here
Restoring files from backup before removing the ransomware is ineffective because the malware frequently installs persistence mechanisms such as scheduled tasks, services, or startup registry keys that re-execute the encryptor on the next reboot. The restored data would simply be re-encrypted, and the operator would lose both time and a trusted recovery copy. Backups should be restored only after the root cause is identified, the system is rebuilt or cleaned, and the integrity of the backup media is confirmed—preferably from an immutably offline storage location.
- ✗
Pay the ransom
Why it's wrong here
Paying the ransom is universally discouraged by law enforcement and cybersecurity agencies because it funds criminal infrastructure and does not guarantee that the decryption key will be provided—studies show a significant fraction of payers never recover their files. Moreover, a paying organization signals that it is a lucrative repeat target, increasing the likelihood of future attacks, and the transaction may violate sanction laws if the threat actor is designated. Appropriate response focuses on restoring from validated backups, eradicating the threat, and reporting the incident to authorities rather than negotiating with adversaries.
Go deeper
Related to this question
Learn chapter
Disaster Recovery Planning
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.