Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A technician is creating a checklist for responding to a ransomware incident. According to best practices, which step should be performed FIRST after the ransomware is detected?

⚠ Common exam trap

Test-takers frequently think identifying the ransomware strain (Option A) is the logical first step for choosing a decryption tool, but CompTIA emphasizes containment before investigation to prevent further damage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disconnect the infected system from the network

The first priority when ransomware is detected is to contain the infection and prevent it from spreading to other systems on the network. Disconnecting the infected system from the network (Option B) immediately isolates the threat, stopping the ransomware from encrypting network shares, communicating with command-and-control servers, or propagating laterally. This containment step is critical before any analysis or recovery actions are taken.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Identify the ransomware strain

    Why it's wrong here

    Performing research to identify the ransomware strain (e.g., by hashing the binary, analyzing the ransom note, or querying C2 indicators) is useful for determining whether a public decryptor exists and for threat intelligence sharing. However, this analysis should be deferred until after the infected host is isolated, because active analysis on a live network connection allows the ransomware to continue encrypting mapped drives, escalating privileges, and communicating with its command-and-control server. In the incident response workflow, containment (like network disconnection) must precede forensics and threat identification to limit blast radius.

  • ✓

    Disconnect the infected system from the network

    Why this is correct

    Disconnecting the infected system from the network is the immediate containment action that severs the ransomware's command-and-control channel, stopping the encryption key exchange and halting lateral movement to adjacent hosts. This includes unplugging Ethernet, disabling Wi-Fi, and optionally blocking outbound traffic at the switch/firewall level to preserve evidence while preventing communication. According to standard IR playbooks, isolation is the top priority after detection, because every minute on the network allows the ransomware to propagate and encrypt more data.

  • ✗

    Restore files from backup

    Why it's wrong here

    Restoring files from backup before removing the ransomware is ineffective because the malware frequently installs persistence mechanisms such as scheduled tasks, services, or startup registry keys that re-execute the encryptor on the next reboot. The restored data would simply be re-encrypted, and the operator would lose both time and a trusted recovery copy. Backups should be restored only after the root cause is identified, the system is rebuilt or cleaned, and the integrity of the backup media is confirmed—preferably from an immutably offline storage location.

  • ✗

    Pay the ransom

    Why it's wrong here

    Paying the ransom is universally discouraged by law enforcement and cybersecurity agencies because it funds criminal infrastructure and does not guarantee that the decryption key will be provided—studies show a significant fraction of payers never recover their files. Moreover, a paying organization signals that it is a lucrative repeat target, increasing the likelihood of future attacks, and the transaction may violate sanction laws if the threat actor is designated. Appropriate response focuses on restoring from validated backups, eradicating the threat, and reporting the incident to authorities rather than negotiating with adversaries.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.