220-1102 Security Practice Question
A security administrator notices that multiple user workstations are infected with the same strain of ransomware. The administrator isolates the infected systems from the network. Which of the following should the administrator do NEXT according to incident response procedures?
⚠ Common exam trap
A common mix-up: candidates confuse 'conduct a root cause analysis' (a post-incident step) with 'identify the source of the infection' (an immediate eradication step), leading them to choose D instead of A.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify the source of the infection
According to the NIST SP 800-61 incident response framework, after containment (isolating infected systems), the next step is eradication, which begins with identifying the source of the infection. Without determining the initial vector (e.g., phishing email, exploit kit, or malicious USB), the same strain of ransomware could reinfect systems after cleanup. This step ensures the root entry point is removed before proceeding to recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identify the source of the infection
Why this is correct
Identifying the infection source is the immediate next step after isolation because it reveals the attack vector, propagation method, and associated indicators of compromise (IoCs). Without this, the containment strategy is blind, and the team cannot safely eradicate the threat or prevent reinfection from the same strain. In practice, this involves correlating endpoint telemetry, email gateway logs, and network flows to pinpoint the delivery mechanism.
- ✗
Restore operations from backups
Why it's wrong here
Restoring operations from backups is premature because the infection is still present and the source is unknown. If backups are restored before eradication, the malware may be reintroduced via the original vector or through compromised backup data. This action belongs to the recovery phase, which occurs only after the threat has been fully removed and verified clean.
- ✗
Notify law enforcement
Why it's wrong here
Notifying law enforcement is not the immediate technical action after isolation; it is a legal or policy-driven step that may run in parallel. In many incidents, law enforcement notification is delayed until evidence is preserved and the organization's incident response plan is followed. Premature notification without preserving forensic evidence could compromise later investigation, and it does not help contain the active infection.
- ✗
Conduct a root cause analysis
Why it's wrong here
A root cause analysis is part of the lessons-learned phase, occurring after the incident has been contained, eradicated, and operations restored. Identifying the source of the infection is a more granular, tactical step that feeds into containment, whereas root cause analysis is a broader, post-incident review of systemic weaknesses. Performing it now would divert resources from the immediate priority of stopping the spread.
Go deeper
Related to this question
Learn chapter
Incident Response for A+
Key term
Eradication
Eradication is the phase in incident response where the root cause of a security breach is completely removed from the system to prevent the attack from happening again.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.