Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A technician is following incident response procedures after a workstation was infected with malware. The technician has isolated the workstation from the network and created a forensic image of the hard drive. What should the technician do NEXT?

⚠ Common exam trap

Many exam-takers confuse the order of incident response steps, jumping to eradication (reinstalling OS) or reporting before completing the analysis phase, which is critical for preventing recurrence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify the root cause of the infection

After isolating the workstation and creating a forensic image, the next step in the incident response process is to identify the root cause of the infection. This ensures that the vulnerability or entry vector (e.g., phishing email, unpatched software, weak credentials) is understood and remediated before any cleanup or recovery begins. Skipping root cause analysis risks reinfection or incomplete containment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reinstall the operating system on the workstation

    Why it's wrong here

    Reinstallation wipes the entire disk, destroying the very filesystem artifacts, MFT records, and unallocated-space remnants needed to trace how the malware first entered. It is a recovery step that must wait until root cause analysis identifies the infection vector, such as an unpatched service or malicious email attachment, because reinstalling without addressing that vector guarantees reinfection. Additionally, any network persistence like scheduled tasks on other hosts or C2 beaconing configurations would be missed, leaving lateral movement paths operational.

  • ✗

    Scan the workstation with an antivirus tool

    Why it's wrong here

    Running an antivirus scan on the original workstation alters live forensic evidence: it updates file access times, writes quarantine logs, and can trigger the malware to execute further, potentially encrypting or deleting data. Because the technician already captured a forensic image, the proper next step is to analyze that image in a read-only, sandboxed environment using static and dynamic analysis techniques. This preserves the original as evidence and prevents contamination that could make legal or investigative findings unreliable.

  • ✗

    Document the findings and report to management

    Why it's wrong here

    Although documentation is a continuous thread throughout the IR lifecycle, reporting to management at this stage is premature because the incident timeline and blast radius are still unknown. The next action after evidence collection is to analyze the forensic data to determine the entry point, scope of compromise, and indicators of compromise (IOCs). Only after root cause identification can the team provide accurate, meaningful status updates to management; premature reports risk conveying incorrect assumptions or unverified conclusions that could misguide executive decisions.

  • ✓

    Identify the root cause of the infection

    Why this is correct

    After isolating the workstation and capturing a forensic image, the correct next step is analyzing that image alongside logs to determine the root cause—how the malware entered, what user actions or vulnerabilities enabled it, and which systems were affected. This root cause analysis directly informs eradication actions, such as removing specific payloads, patching a vulnerability, or revoking compromised credentials, ensuring that the threat is completely neutralized. Skipping this step leaves the organization vulnerable to the same attack path or hidden backdoors, making a clean reinstall worthless.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.