Courseiva
Operational Procedures →hardMultiple Choice

220-1102 Operational Procedures Practice Question

A user reports that their workstation is infected with ransomware, and all files on the local drive as well as mapped network drives are encrypted. The technician has already isolated the workstation by unplugging the network cable and powering off the machine. According to incident response best practices, what should the technician do NEXT?

⚠ Common exam trap

The trap here is that candidates might think the next step is to immediately start recovery or eradication actions like restoring backups or running antivirus scans, but the correct next step is to escalate to the incident response team to ensure proper handling and avoid destroying evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Escalate the incident to the incident response team

According to incident response best practices, after isolating the infected workstation, the next step is to escalate the incident to the incident response team. This ensures that the appropriate experts handle the ransomware attack, assess the scope, and coordinate containment, eradication, and recovery. The technician should not attempt remediation steps like restoring files or reimaging without proper guidance, as this could destroy evidence or allow the ransomware to spread further.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restore the encrypted files from the most recent backup

    Why it's wrong here

    Restoration from backup is a recovery step that should occur after the incident has been analyzed and the root cause is understood. Doing it too early may risk re-infection if the vector is still active.

  • ✗

    Wipe the drive and reimage the workstation

    Why it's wrong here

    Wiping the drive and reimaging is a destructive recovery action that should be deferred until the incident has been contained and properly investigated. Performing it immediately destroys volatile data and malware artifacts needed for forensic analysis, and it also misses persistence mechanisms that may reside outside the operating system partition, such as firmware or bootloader implants. Escalation and root-cause analysis must precede reimaging, otherwise the clean-installed workstation could be immediately reintroduced to the same active attack vector.

  • ✓

    Escalate the incident to the incident response team

    Why this is correct

    Escalating to the incident response team is the correct immediate action because ransomware constitutes a critical security incident that must be handled outside the scope of routine workstation repair. The IR team is authorized to coordinate evidence preservation, contain the threat to prevent lateral movement, and ensure compliance with legal, regulatory, and client-notification requirements. Attempting independent remediation without escalation could violate incident response policy, impair forensic integrity, and leave network-wide scope undetermined.

  • ✗

    Run a full antivirus scan on the isolated machine

    Why it's wrong here

    Running a full antivirus scan on an isolated, ransomware-infected workstation is ineffective because modern ransomware often completes mass encryption before any scan can run, and antivirus tools generally cannot reverse encryption without the cryptographic key. The scan itself may cause heavy disk I/O that triggers the malware to encrypt additional files or switch to destructive behavior like shadow-copy deletion. Since the machine is already isolated, the safer course is to preserve the system state for the IR team rather than altering it with tools that are misaligned with the actual threat.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A technician receives a report from a user that their workstation is displaying a ransomware note and files are being encrypted. The technician has already isolated the workstation from the network. According to incident response procedures, which of the following is the NEXT step the technician should take?

medium
  • A.Run a full antivirus scan on the isolated workstation
  • B.Attempt to decrypt the files using online tools
  • ✓ C.Notify the appropriate internal security contact
  • D.Restore the user's files from the most recent backup

Why C: According to incident response procedures, after isolating the affected system, the next step is to notify the appropriate internal security contact or team. This ensures that the incident is properly escalated and handled by trained personnel. Running antivirus scans, attempting decryption, or restoring from backup are remediation steps that should be guided by the security team and may destroy evidence if done prematurely.

Variation 2. A user reports that their workstation is infected with ransomware. The technician instructs the user to disconnect the network cable immediately. According to incident response best practices, what should the technician do NEXT?

medium
  • A.Restore the system from the latest backup immediately.
  • ✓ B.Document the incident and escalate to the security team.
  • C.Run a full antivirus scan on the infected workstation.
  • D.Reinstall the operating system.

Why B: After isolating the infected workstation by disconnecting the network cable, the next step per incident response best practices is to document the incident and escalate to the security team. This ensures proper chain of custody, evidence preservation, and that the incident is handled by trained personnel who can perform forensic analysis and coordinate containment. Skipping documentation and escalation risks losing critical forensic data and violating organizational incident response procedures.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.