easyMultiple ChoiceObjective-mapped
220-1102 Practice Question: During a security incident, a user's files have…
During a security incident, a user's files have been renamed with a '.encrypted' extension, and a ransom note demands Bitcoin to restore them. The user has no backups. What is the most appropriate immediate action?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the computer from the network immediately.
Ransomware encrypts files, and paying the ransom does not guarantee decryption. The correct first step is to isolate the infected system to prevent the malware from spreading to network shares or other devices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pay the ransom to regain access quickly.
Why it's wrong here
Paying the ransom is generally discouraged by cybersecurity experts and law enforcement for several critical reasons. There is no guarantee that the attackers will provide a working decryption key, and even if they do, the decryption process can be complex, incomplete, or introduce further vulnerabilities. Furthermore, paying directly funds criminal enterprises, encouraging more attacks and validating their illicit business model, which ultimately makes other potential victims more vulnerable.
- ✓
Disconnect the computer from the network immediately.
Why this is correct
Disconnecting the computer from the network immediately is the most critical first step in containing a ransomware infection. This action prevents the malware from encrypting additional local files, stops it from accessing and encrypting shared network drives or cloud storage, and halts its potential spread to other systems or network segments. Isolating the compromised machine effectively limits the scope of the attack and preserves uninfected data, which is crucial for incident response.
- ✗
Run a full antivirus scan to remove the malware.
Why it's wrong here
While running a full antivirus scan is a necessary step for malware eradication, it does not address the immediate problem of already encrypted files. An antivirus program can detect and remove the ransomware executable, but it lacks the capability to reverse the cryptographic process that has rendered the user's data inaccessible. The primary concern in this scenario is data recovery, which an antivirus scan alone cannot achieve for data that has already been scrambled by encryption.
- ✗
Restart the computer in Safe Mode and attempt file recovery.
Why it's wrong here
Restarting the computer in Safe Mode does not provide any inherent mechanism to decrypt files that have been locked by ransomware. Safe Mode is designed to troubleshoot system issues by loading a minimal set of drivers and services, which can be useful for removing persistent malware or resolving driver conflicts. However, it does not magically restore access to cryptographically scrambled data, as the encryption key remains with the attacker, making the files unreadable regardless of the operating mode.
Go deeper
Related to this question
Learn chapter
Malware Types and Removal
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Decryption
Decryption is the process of converting encrypted or scrambled data back into its original, readable form using a specific key or method.
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.