Courseiva
Operational Procedures →hardMultiple Choice

220-1102 Operational Procedures Practice Question

A technician is responding to a security incident where malware has been detected on several workstations. According to industry best practices (such as NIST or SANS), which step should the technician perform FIRST after confirming the incident?

⚠ Common exam trap

The 220-1102 exam often tests the order of the incident response phases (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned), and the trap here is that candidates mistakenly jump to eradication or root-cause analysis because they think removing the malware or understanding the attack is the most urgent priority, ignoring the critical need to stop active spread first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Contain the incident to prevent further spread

According to NIST SP 800-61 and SANS incident response frameworks, the containment phase immediately follows confirmation of an incident. The technician must first isolate affected workstations from the network (e.g., disconnecting Ethernet cables, disabling Wi-Fi, or using VLAN ACLs) to prevent the malware from spreading laterally or communicating with command-and-control servers. Containment preserves forensic evidence and limits damage before any eradication or root-cause analysis begins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Identify the root cause and scope of the incident

    Why it's wrong here

    While identifying the root cause and scope is essential for understanding the breach, it is a time-intensive process that must follow immediate containment. Performing a deep-dive analysis first allows the malware to continue propagating and expanding its foothold, potentially compromising additional systems. The NIST lifecycle places detection and analysis before containment, but in practice, containment is the urgent priority once an active threat is confirmed.

  • ✓

    Contain the incident to prevent further spread

    Why this is correct

    Upon confirming an active malware infection, the immediate priority is containment to halt lateral movement and prevent further compromise. Actions include isolating affected hosts via network segmentation, revoking privileged credentials, and blocking command-and-control traffic at egress points. This aligns with the NIST incident response lifecycle, where containment precedes eradication and recovery, ensuring the threat is neutralized before any cleanup or restoration begins.

  • ✗

    Eradicate the malware from all affected systems

    Why it's wrong here

    Eradication—removing malware via antivirus scans, file deletion, or system reimaging—is a critical step, but executing it before containment is futile and dangerous. Without first isolating the infection, the malware can reinfect cleared systems through shared network shares, RDP, or active C2 channels. Proper incident response methodology mandates that containment occur first to establish a clean boundary, after which eradication can be performed without interference.

  • ✗

    Document all findings in the incident report

    Why it's wrong here

    Documentation is an ongoing responsibility throughout incident response, but suspending active response efforts to compile a full incident report would allow the malware to spread unabated. While initial notes and timestamps must be recorded for legal and forensic validity, comprehensive documentation follows the containment phase. The immediate duty after confirmation is to act, not to write; otherwise, the incident scope escalates and the documentation itself becomes incomplete and inaccurate.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A technician discovers that a user's workstation has been compromised. Logs indicate that sensitive data has been exfiltrated. According to incident response best practices, which action should the technician take FIRST?

medium
  • ✓ A.Disconnect the workstation from the network
  • B.Run a full antivirus scan
  • C.Report the incident to law enforcement
  • D.Rebuild the workstation

Why A: According to incident response best practices, the first priority is to contain the breach and prevent further data exfiltration. Disconnecting the workstation from the network immediately stops the attacker's ability to communicate with the compromised system, halting data transfer and preventing lateral movement. This aligns with the NIST SP 800-61 incident response framework, which emphasizes containment before eradication or recovery.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.