220-1102 Security Practice Question
A user reports that their computer displays a pop-up claiming their files are encrypted and demanding payment in Bitcoin to decrypt them. The user did not click on any suspicious links. The technician suspects ransomware. What is the FIRST step the technician should take?
⚠ Common exam trap
Test-takers frequently choose to run an antivirus scan first, thinking remediation is the priority, but CompTIA emphasizes containment (isolation) as the immediate step to limit damage before any recovery or scanning actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the computer from the network.
The first step is to disconnect the computer from the network to contain the ransomware and prevent it from spreading to other systems via network shares, SMB protocols, or lateral movement. This isolation preserves forensic evidence and stops the encryption process from affecting additional drives or mapped network resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pay the ransom to retrieve the files.
Why it's wrong here
Paying the ransom is ineffective from a security standpoint because cybercriminals often fail to provide working decryption tools even after payment, and there is no legal or technical guarantee of data recovery. Additionally, sending money funds criminal infrastructure and directly encourages the continued development of ransomware, potentially making you a repeat target. Law enforcement agencies, including the FBI, explicitly advise against paying as it does not remediate the underlying vulnerability that allowed the infection.
- ✗
Reimage the computer immediately.
Why it's wrong here
Reimaging the computer immediately destroys all volatile and non-volatile evidence, such as the ransomware binary, runtime artifacts in memory (if the machine is still on), and valuable log entries that could reveal the initial attack vector. This action also bypasses the critical requirement to contain the threat on the network; if the malware has already spread to other systems or shares, reimaging only this device leaves the broader outbreak unresolved. The correct order is to isolate the system first, then preserve forensic evidence, and only after containment is confirmed can you rebuild the image.
- ✓
Disconnect the computer from the network.
Why this is correct
Disconnecting the computer from the network is the proper first response because it creates an immediate hard boundary that stops the ransomware from contacting its command-and-control server and prevents it from scanning or encrypting network-attached drives. This action also halts any active lateral movement by the attacker into other hosts on the same local network, which is a primary objective of ransomware containment. Physically unplugging the Ethernet cable or disabling the wireless adapter is the most direct way to achieve this isolation without relying on software that may already be compromised.
- ✗
Run a full antivirus scan.
Why it's wrong here
Running a full antivirus scan on an actively infected and network-connected system is insufficient as a first response because the scanner is running under a compromised kernel and its findings cannot be trusted; the ransomware may also detect on-access scanning and encrypt additional files as the scanner opens them for inspection. More importantly, the scan does nothing to prevent the ransomware from communicating with its C2 server or spreading to adjacent systems, so the threat continues to propagate while the scan consumes resources. Containment by disconnection must precede any remediation attempt, including antivirus scanning, and the scan should later be performed from a clean, controlled environment or using a rescue image.
Go deeper
Related to this question
Learn chapter
Malware Classification: Virus, Worm, Ransomware, Rootkit
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
SMB
SMB is a network file-sharing protocol that allows applications to read, write, and request services from server programs in a computer network.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.