220-1102 Incident Response Phases Practice Question
A user reports that their workstation is infected with ransomware. The technician isolates the computer from the network by disconnecting the network cable. What should the technician do NEXT according to incident response procedures?
⚠ Common exam trap
Many candidates confuse the order of incident response steps, thinking forensic collection (Option D) or antivirus scanning (Option A) should come immediately after isolation, when in fact eradication and recovery (wipe and restore) take precedence to stop the spread and restore operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Wipe the hard drive and restore from a known good backup
After isolating the infected workstation by disconnecting the network cable, the next step in incident response is to contain the threat and begin recovery. Wiping the hard drive and restoring from a known good backup (Option C) follows the NIST SP 800-61 recovery phase, ensuring the ransomware is completely removed and the system is returned to a clean state. Running a full antivirus scan (Option A) is unreliable because ransomware often disables or evades antivirus software, and scanning could trigger further encryption or damage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on the workstation
Why it's wrong here
Running an antivirus scan on a ransomware-infected workstation is an unreliable eradication method because modern ransomware can disable or evade endpoint protection and the primary damage—file encryption—is often already complete. AV detection signatures may not yet cover the specific ransomware variant, and even if files are quarantined, encrypted user data remains inaccessible. The safer incident-response approach is to treat the system as compromised, wipe it, and restore from a verified clean backup rather than spending time on a scan that does not guarantee recovery.
- ✗
Notify law enforcement and the company's legal department
Why it's wrong here
While notifying law enforcement and legal counsel may eventually be necessary for compliance, insurance, or criminal investigation, it does nothing to stop the spread of ransomware or recover encrypted files. The immediate technical priority is containment—isolating the workstation from the network—and beginning eradication/recovery steps. Legal notification is a parallel process that can happen while technicians wipe and restore, but it is not the next operational action to resolve the infection.
- ✓
Wipe the hard drive and restore from a known good backup
Why this is correct
Wiping the hard drive and restoring from a known good backup is the definitive remediation because ransomware can persist through normal deletions or even hide in boot sectors, and you cannot trust that a scan removed every component. A full wipe eliminates all malicious files and any changes to the operating system, while restoring user data from a clean offline backup brings operations back without paying the ransom. Before restoring, verify the backup predates the initial infection and is free of the ransomware payload, and ensure the restored system is patched to prevent re-infection.
- ✗
Collect forensic data for analysis
Why it's wrong here
Forensic data collection is often a deliberate pre-eradication step because wiping the drive destroys evidential artifacts and complicates attribution or legal prosecution, but it is not always the immediate priority in every incident response playbook. Many organizations prioritize containment and rapid recovery to minimize business disruption, especially when clean backups exist, and thus skip or defer forensics. If legal action is anticipated, preserve memory and disk images before wiping, but this decision is separate from the core remediation objective and may be outweighed by recovery urgency.
Go deeper
Related to this question
Learn chapter
Electrical Safety Procedures
Key term
Backup
A backup is a copy of computer data taken and stored separately so that the original data can be restored if it is lost, damaged, or corrupted.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.