Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports that their computer displays a pop-up claiming their files are encrypted and demanding payment in Bitcoin to decrypt them. The user did not click on any suspicious links. The technician suspects ransomware. What is the FIRST step the technician should take?

⚠ Common exam trap

Test-takers frequently choose to run an antivirus scan first, thinking remediation is the priority, but CompTIA emphasizes containment (isolation) as the immediate step to limit damage before any recovery or scanning actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disconnect the computer from the network.

The first step is to disconnect the computer from the network to contain the ransomware and prevent it from spreading to other systems via network shares, SMB protocols, or lateral movement. This isolation preserves forensic evidence and stops the encryption process from affecting additional drives or mapped network resources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pay the ransom to retrieve the files.

    Why it's wrong here

    Paying the ransom is ineffective from a security standpoint because cybercriminals often fail to provide working decryption tools even after payment, and there is no legal or technical guarantee of data recovery. Additionally, sending money funds criminal infrastructure and directly encourages the continued development of ransomware, potentially making you a repeat target. Law enforcement agencies, including the FBI, explicitly advise against paying as it does not remediate the underlying vulnerability that allowed the infection.

  • ✗

    Reimage the computer immediately.

    Why it's wrong here

    Reimaging the computer immediately destroys all volatile and non-volatile evidence, such as the ransomware binary, runtime artifacts in memory (if the machine is still on), and valuable log entries that could reveal the initial attack vector. This action also bypasses the critical requirement to contain the threat on the network; if the malware has already spread to other systems or shares, reimaging only this device leaves the broader outbreak unresolved. The correct order is to isolate the system first, then preserve forensic evidence, and only after containment is confirmed can you rebuild the image.

  • ✓

    Disconnect the computer from the network.

    Why this is correct

    Disconnecting the computer from the network is the proper first response because it creates an immediate hard boundary that stops the ransomware from contacting its command-and-control server and prevents it from scanning or encrypting network-attached drives. This action also halts any active lateral movement by the attacker into other hosts on the same local network, which is a primary objective of ransomware containment. Physically unplugging the Ethernet cable or disabling the wireless adapter is the most direct way to achieve this isolation without relying on software that may already be compromised.

  • ✗

    Run a full antivirus scan.

    Why it's wrong here

    Running a full antivirus scan on an actively infected and network-connected system is insufficient as a first response because the scanner is running under a compromised kernel and its findings cannot be trusted; the ransomware may also detect on-access scanning and encrypt additional files as the scanner opens them for inspection. More importantly, the scan does nothing to prevent the ransomware from communicating with its C2 server or spreading to adjacent systems, so the threat continues to propagate while the scan consumes resources. Containment by disconnection must precede any remediation attempt, including antivirus scanning, and the scan should later be performed from a clean, controlled environment or using a rescue image.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.