220-1102 Operational Procedures Practice Question
A help desk technician has identified a malware infection on a user's workstation. The technician has disconnected the computer from the network to contain the infection. According to the company's incident response plan, what should the technician do NEXT?
⚠ Common exam trap
Candidates often confuse the 'containment' phase with the 'eradication' phase, mistakenly jumping to reimaging (Option A) instead of following the proper incident response order: containment, evidence collection, analysis, eradication, and recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a forensic analysis of the infected system to gather evidence
After containment (disconnecting from the network), the next step in a structured incident response plan is to collect evidence for forensic analysis. This preserves the state of the system for investigation, which is critical for identifying the malware type, infection vector, and scope of compromise before any remediation steps like reimaging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reimage the workstation to ensure the malware is removed
Why it's wrong here
Reimaging wipes the entire storage volume, permanently destroying volatile data in memory, prefetch/superfetch files, and malware artifacts embedded in the filesystem that are essential for forensic investigation. It is a last-resort remediation step that should only be executed after acquiring a forensic image and documenting the chain of custody. Performing it immediately violates the principle of evidence preservation and can compromise legal proceedings, insurance claims, and the ability to identify the attack vector.
- ✓
Perform a forensic analysis of the infected system to gather evidence
Why this is correct
Forensic analysis follows the order of volatility: capturing RAM first to recover encryption keys, running processes, network connections, and in-memory malware, then creating a bit-for-bit disk image using hardware write blockers to ensure the original evidence is unaltered. This collected evidence enables investigators to determine the exact malware family, entry point, and scope of compromise, which is necessary for eradication and for meeting regulatory breach-notification requirements. Without this step, critical indicators of compromise (IOCs) are lost, making it impossible to fully remediate the threat or support potential legal action.
- ✗
Report the incident to the company's management
Why it's wrong here
Reporting to management is a critical communication step in incident response, but doing it as the first action squanders the opportunity to preserve volatile evidence that decays within seconds or minutes, such as running processes and memory-resident malware. Management likely expects a technical update with root cause analysis, which can only be provided after forensic examination. An initial report without evidence may lead to incorrect assumptions, delayed containment, and failure to comply with legal obligations like data-breach notification laws, so the correct sequence is to gather evidence first, then report.
- ✗
Remove the malware using an antivirus scan
Why it's wrong here
Running an antivirus scan on a live infected system alters the forensic state: the AV engine may quarantine or delete malware files, modify registry keys, and overwrite filesystem timestamps, rendering the evidence inadmissible and unusable for a detailed investigation. Furthermore, many advanced malware strains employ rootkits and polymorphic code that evade signature-based detection, so a clean scan result provides false assurance of eradication. The proper approach is to perform forensic imaging before any remediation attempt, allowing analysts to neutralize the threat without sacrificing forensic integrity.
Go deeper
Related to this question
Learn chapter
Troubleshoot: Corrupt User Profile
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.