Courseiva
Operational Procedures →mediumMultiple Choice

220-1102 Operational Procedures Practice Question

A user reports that their workstation is infected with ransomware. The technician instructs the user to disconnect the network cable immediately. According to incident response best practices, what should the technician do NEXT?

⚠ Common exam trap

The trap here is that candidates often jump to 'restore from backup' or 'run antivirus' as immediate actions, but CompTIA tests the understanding that containment and escalation must precede any remediation to preserve evidence and follow proper incident response procedures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the incident and escalate to the security team.

After isolating the infected workstation by disconnecting the network cable, the next step per incident response best practices is to document the incident and escalate to the security team. This ensures proper chain of custody, evidence preservation, and that the incident is handled by trained personnel who can perform forensic analysis and coordinate containment. Skipping documentation and escalation risks losing critical forensic data and violating organizational incident response procedures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restore the system from the latest backup immediately.

    Why it's wrong here

    Restoring from backup immediately is premature while the attack is still undiagnosed; if the ransomware had network-level persistence or the backup share was also encrypted, the restore will simply reinfect the system. Moreover, an uncoordinated restore overwrites volatile data and log artifacts that the security team needs to determine the initial attack vector. The correct sequence is to document, assess scope, and preserve evidence before any recovery step.

  • ✓

    Document the incident and escalate to the security team.

    Why this is correct

    This is the mandated next step in a structured incident response: the technician must create an accurate record of the observed symptoms, time, and forensic artifacts before any remediation. Escalating to the security team ensures that trained analysts can execute containment, root-cause analysis, and legal holds, preserving chain of custody for potential litigation. Documentation also provides the baseline data needed to verify the effectiveness of later remediation and prevent recurrence.

  • ✗

    Run a full antivirus scan on the infected workstation.

    Why it's wrong here

    Running a full on-demand antivirus scan is unreliable against ransomware, which may use fileless techniques, packed binaries, or trusted administrative tools that evade signature catalogues. It also modifies file timestamps and performs heavy I/O, potentially allowing the ransomware process to detect the scan and accelerate encryption or exfiltration. The scan may quarantine or delete only user-visible files while missing the actor's native code, thereby destroying evidence without actually resolving the incident.

  • ✗

    Reinstall the operating system.

    Why it's wrong here

    Reinstalling the operating system is a recovery/eradication step that belongs at the end of the incident response lifecycle, not at first discovery, because it irreversibly destroys the digital evidence needed to trace the breach and can let ransomware persist in firmware or unexamined secondary volumes. Also, reimaging a single workstation does not remediate lateral movement or compromised credentials that allowed the ransomware to spread. The technician must first document, escalate, and preserve data for investigation and possibly law enforcement.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.