220-1102 Operational Procedures Practice Question
A user reports that their workstation is infected with ransomware, and all files on the local drive as well as mapped network drives are encrypted. The technician has already isolated the workstation by unplugging the network cable and powering off the machine. According to incident response best practices, what should the technician do NEXT?
⚠ Common exam trap
The trap here is that candidates might think the next step is to immediately start recovery or eradication actions like restoring backups or running antivirus scans, but the correct next step is to escalate to the incident response team to ensure proper handling and avoid destroying evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate the incident to the incident response team
According to incident response best practices, after isolating the infected workstation, the next step is to escalate the incident to the incident response team. This ensures that the appropriate experts handle the ransomware attack, assess the scope, and coordinate containment, eradication, and recovery. The technician should not attempt remediation steps like restoring files or reimaging without proper guidance, as this could destroy evidence or allow the ransomware to spread further.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restore the encrypted files from the most recent backup
Why it's wrong here
Restoration from backup is a recovery step that should occur after the incident has been analyzed and the root cause is understood. Doing it too early may risk re-infection if the vector is still active.
- ✗
Wipe the drive and reimage the workstation
Why it's wrong here
Wiping the drive and reimaging is a destructive recovery action that should be deferred until the incident has been contained and properly investigated. Performing it immediately destroys volatile data and malware artifacts needed for forensic analysis, and it also misses persistence mechanisms that may reside outside the operating system partition, such as firmware or bootloader implants. Escalation and root-cause analysis must precede reimaging, otherwise the clean-installed workstation could be immediately reintroduced to the same active attack vector.
- ✓
Escalate the incident to the incident response team
Why this is correct
Escalating to the incident response team is the correct immediate action because ransomware constitutes a critical security incident that must be handled outside the scope of routine workstation repair. The IR team is authorized to coordinate evidence preservation, contain the threat to prevent lateral movement, and ensure compliance with legal, regulatory, and client-notification requirements. Attempting independent remediation without escalation could violate incident response policy, impair forensic integrity, and leave network-wide scope undetermined.
- ✗
Run a full antivirus scan on the isolated machine
Why it's wrong here
Running a full antivirus scan on an isolated, ransomware-infected workstation is ineffective because modern ransomware often completes mass encryption before any scan can run, and antivirus tools generally cannot reverse encryption without the cryptographic key. The scan itself may cause heavy disk I/O that triggers the malware to encrypt additional files or switch to destructive behavior like shadow-copy deletion. Since the machine is already isolated, the safer course is to preserve the system state for the IR team rather than altering it with tools that are misaligned with the actual threat.
Go deeper
Related to this question
Learn chapter
BitLocker Drive Encryption
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A technician receives a report from a user that their workstation is displaying a ransomware note and files are being encrypted. The technician has already isolated the workstation from the network. According to incident response procedures, which of the following is the NEXT step the technician should take?
medium- A.Run a full antivirus scan on the isolated workstation
- B.Attempt to decrypt the files using online tools
- ✓ C.Notify the appropriate internal security contact
- D.Restore the user's files from the most recent backup
Why C: According to incident response procedures, after isolating the affected system, the next step is to notify the appropriate internal security contact or team. This ensures that the incident is properly escalated and handled by trained personnel. Running antivirus scans, attempting decryption, or restoring from backup are remediation steps that should be guided by the security team and may destroy evidence if done prematurely.
Variation 2. A user reports that their workstation is infected with ransomware. The technician instructs the user to disconnect the network cable immediately. According to incident response best practices, what should the technician do NEXT?
medium- A.Restore the system from the latest backup immediately.
- ✓ B.Document the incident and escalate to the security team.
- C.Run a full antivirus scan on the infected workstation.
- D.Reinstall the operating system.
Why B: After isolating the infected workstation by disconnecting the network cable, the next step per incident response best practices is to document the incident and escalate to the security team. This ensures proper chain of custody, evidence preservation, and that the incident is handled by trained personnel who can perform forensic analysis and coordinate containment. Skipping documentation and escalation risks losing critical forensic data and violating organizational incident response procedures.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.