220-1102 Security Practice Question
A user reports that their Windows 10 computer shows a ransomware message demanding payment to decrypt files. According to standard incident response procedures, what should the technician do FIRST?
⚠ Common exam trap
Watch out — candidates often choose to run an antivirus scan first, thinking it will remove the ransomware, but the correct first step is always containment to prevent further damage, not remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the computer from the network
Disconnecting the computer from the network is the immediate first step in incident response for ransomware. This containment action prevents the ransomware from encrypting additional files on network shares, communicating with its command-and-control (C2) server, or spreading laterally to other systems. The priority is to stop the attack from escalating before any remediation steps are taken.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pay the ransom to quickly regain access to files
Why it's wrong here
Paying the ransom is a high-risk action that provides no technical guarantee of decryption; attackers frequently take payment and withhold the decryption key. It also funds criminal infrastructure, may violate regulations or sanctions, and identifies the victim as willing to pay, which can make repeat attacks more likely. Security best practice directs organizations to treat payment as a last resort, considered only after exhausting all alternative recovery methods.
- ✓
Disconnect the computer from the network
Why this is correct
Disconnecting the computer from the network is the correct first response because it physically severs the attacker's command-and-control channel and halts the ransomware's ability to encrypt mapped drives, network shares, or adjacent endpoints. This containment step also limits potential data exfiltration and preserves volatile evidence, such as active network connections in memory or the encryption routine's artifacts, for later forensic analysis. Immediate isolation is the foundational move in incident response before any scanning or recovery is attempted.
- ✗
Run a full antivirus scan
Why it's wrong here
Running a full antivirus scan during an active ransomware infection can actually accelerate the damage: as the scan reads files, the already-resident ransomware may encrypt them in real time, and a zero-day variant may not match existing signatures, rendering the scan useless. Additionally, antivirus remediation tools that attempt to quarantine files while the malicious process is running can cause system instability, incomplete detection, or trigger the ransomware to engage in destructive self-deletion or mass encryption as a defensive measure. Proper sequence requires containment first, then an offline or forensically prepared scan.
- ✗
Restore files from a recent backup
Why it's wrong here
Restoring files immediately from backup is premature because the network may still be compromised; if the ransomware or its persistence mechanism remains active, it will encrypt restored files again or re-infect the machine. A valid restore also depends on verifying that the backup set itself is clean and unencrypted, because many ransomware strains intentionally encrypt or delete local/online backups before escalating. Incident handling requires the technician to first contain the threat, identify the ransomware strain, and preserve forensic evidence, only then ensuring the chosen backup is clean and safe to restore.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.