220-1102 Operational Procedures Practice Question
A technician is following incident response procedures after a workstation was infected with malware. The technician has isolated the workstation from the network and created a forensic image of the hard drive. What should the technician do NEXT?
⚠ Common exam trap
Many exam-takers confuse the order of incident response steps, jumping to eradication (reinstalling OS) or reporting before completing the analysis phase, which is critical for preventing recurrence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify the root cause of the infection
After isolating the workstation and creating a forensic image, the next step in the incident response process is to identify the root cause of the infection. This ensures that the vulnerability or entry vector (e.g., phishing email, unpatched software, weak credentials) is understood and remediated before any cleanup or recovery begins. Skipping root cause analysis risks reinfection or incomplete containment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reinstall the operating system on the workstation
Why it's wrong here
Reinstallation wipes the entire disk, destroying the very filesystem artifacts, MFT records, and unallocated-space remnants needed to trace how the malware first entered. It is a recovery step that must wait until root cause analysis identifies the infection vector, such as an unpatched service or malicious email attachment, because reinstalling without addressing that vector guarantees reinfection. Additionally, any network persistence like scheduled tasks on other hosts or C2 beaconing configurations would be missed, leaving lateral movement paths operational.
- ✗
Scan the workstation with an antivirus tool
Why it's wrong here
Running an antivirus scan on the original workstation alters live forensic evidence: it updates file access times, writes quarantine logs, and can trigger the malware to execute further, potentially encrypting or deleting data. Because the technician already captured a forensic image, the proper next step is to analyze that image in a read-only, sandboxed environment using static and dynamic analysis techniques. This preserves the original as evidence and prevents contamination that could make legal or investigative findings unreliable.
- ✗
Document the findings and report to management
Why it's wrong here
Although documentation is a continuous thread throughout the IR lifecycle, reporting to management at this stage is premature because the incident timeline and blast radius are still unknown. The next action after evidence collection is to analyze the forensic data to determine the entry point, scope of compromise, and indicators of compromise (IOCs). Only after root cause identification can the team provide accurate, meaningful status updates to management; premature reports risk conveying incorrect assumptions or unverified conclusions that could misguide executive decisions.
- ✓
Identify the root cause of the infection
Why this is correct
After isolating the workstation and capturing a forensic image, the correct next step is analyzing that image alongside logs to determine the root cause—how the malware entered, what user actions or vulnerabilities enabled it, and which systems were affected. This root cause analysis directly informs eradication actions, such as removing specific payloads, patching a vulnerability, or revoking compromised credentials, ensuring that the threat is completely neutralized. Skipping this step leaves the organization vulnerable to the same attack path or hidden backdoors, making a clean reinstall worthless.
Go deeper
Related to this question
Learn chapter
Network Topology Documentation
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.