220-1102 Malware Isolation Practice Question
A technician is supporting a service-desk jump box. The immediate goal is to respond to browser hijacking or suspected infection. Which tool, control, or procedure is the best fit?
⚠ Common exam trap
A common mix-up: candidates confuse 'diagnostic tools' (Event Viewer, System Restore) with 'response procedures,' failing to recognize that the immediate priority in a suspected infection is containment, not analysis or recovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
malware isolation procedure
B is correct because a malware isolation procedure is the immediate, containment-focused response to browser hijacking or suspected infection. This procedure involves disconnecting the affected system from the network to prevent lateral movement and further compromise, aligning with the first step of incident response (isolation) before any remediation or analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Local Users and Groups
Why it's wrong here
Local Users and Groups is a Microsoft Management Console snap-in used to administer local user accounts and group memberships, such as resetting passwords, disabling accounts, or adding users to the Administrators group. For a service desk jump box, the immediate operational or security goal is not identity administration but rather containing a potential threat or diagnosing an active issue. While user management is an important administrative task, it does not address the need for rapid isolation or mitigation, making it an incorrect choice for this scenario.
- ✓
malware isolation procedure
Why this is correct
Malware isolation procedure is correct because the immediate goal when supporting a jump box, especially one used by a service desk, is to contain any suspected infection before it spreads. Isolating the machine—such as disconnecting it from the network or using a hard cutoff—prevents malware from using the jump box as a pivot to compromise other systems, preserves forensic evidence, and aligns with incident response best practices. This direct containment action is the primary step when a jump box is believed to be compromised, making it the most appropriate choice.
- ✗
Event Viewer
Why it's wrong here
Event Viewer is a read-only tool that provides detailed logs for system, security, and application events, which is useful for post-incident analysis or troubleshooting. However, it does not actively mitigate an ongoing threat or contain malware; it only offers insight after the fact. For a service desk jump box, the immediate need is to stop active damage or unauthorized access, not to review logs, so Event Viewer fails to address the stated goal directly.
- ✗
System Restore
Why it's wrong here
System Restore reverts Windows system files, registry keys, and some installed programs to a previous restore point, which might undo certain changes caused by malware. However, it is not a reliable malware removal method, particularly for rootkits or fileless malware, and it can destroy volatile forensic evidence needed for investigation. Additionally, System Restore does not isolate the system from the network or prevent lateral movement, so it is unsuitable as an immediate action for a jump box security incident.
Go deeper
Related to this question
Learn chapter
Incident Response for A+
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.