Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports that their Windows 10 computer shows a ransomware message demanding payment to decrypt files. According to standard incident response procedures, what should the technician do FIRST?

⚠ Common exam trap

Watch out — candidates often choose to run an antivirus scan first, thinking it will remove the ransomware, but the correct first step is always containment to prevent further damage, not remediation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disconnect the computer from the network

Disconnecting the computer from the network is the immediate first step in incident response for ransomware. This containment action prevents the ransomware from encrypting additional files on network shares, communicating with its command-and-control (C2) server, or spreading laterally to other systems. The priority is to stop the attack from escalating before any remediation steps are taken.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pay the ransom to quickly regain access to files

    Why it's wrong here

    Paying the ransom is a high-risk action that provides no technical guarantee of decryption; attackers frequently take payment and withhold the decryption key. It also funds criminal infrastructure, may violate regulations or sanctions, and identifies the victim as willing to pay, which can make repeat attacks more likely. Security best practice directs organizations to treat payment as a last resort, considered only after exhausting all alternative recovery methods.

  • ✓

    Disconnect the computer from the network

    Why this is correct

    Disconnecting the computer from the network is the correct first response because it physically severs the attacker's command-and-control channel and halts the ransomware's ability to encrypt mapped drives, network shares, or adjacent endpoints. This containment step also limits potential data exfiltration and preserves volatile evidence, such as active network connections in memory or the encryption routine's artifacts, for later forensic analysis. Immediate isolation is the foundational move in incident response before any scanning or recovery is attempted.

  • ✗

    Run a full antivirus scan

    Why it's wrong here

    Running a full antivirus scan during an active ransomware infection can actually accelerate the damage: as the scan reads files, the already-resident ransomware may encrypt them in real time, and a zero-day variant may not match existing signatures, rendering the scan useless. Additionally, antivirus remediation tools that attempt to quarantine files while the malicious process is running can cause system instability, incomplete detection, or trigger the ransomware to engage in destructive self-deletion or mass encryption as a defensive measure. Proper sequence requires containment first, then an offline or forensically prepared scan.

  • ✗

    Restore files from a recent backup

    Why it's wrong here

    Restoring files immediately from backup is premature because the network may still be compromised; if the ransomware or its persistence mechanism remains active, it will encrypt restored files again or re-infect the machine. A valid restore also depends on verifying that the backup set itself is clean and unencrypted, because many ransomware strains intentionally encrypt or delete local/online backups before escalating. Incident handling requires the technician to first contain the threat, identify the ransomware strain, and preserve forensic evidence, only then ensuring the chosen backup is clean and safe to restore.

Go deeper

Related to this question

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.