Question 760 of 1,000
mediummultiple choiceObjective-mapped

220-1102 Practice Question: That their workstation is infected with ransomware

This 220-1102 practice question tests your understanding of that their workstation is infected with ransomware. Read the scenario carefully and evaluate each option against the stated constraints before committing to an answer. A key principle to apply: wiping the drive ensures complete ransomware eradication.. Once you have made your selection, read the full explanation to reinforce the concept and understand why each distractor is designed to mislead on exam day.

A user reports that their workstation is infected with ransomware. The technician isolates the computer from the network by disconnecting the network cable. What should the technician do NEXT according to incident response procedures?

Question 1mediummultiple choice
Full question →

A user reports that their workstation is infected with ransomware. The technician isolates the computer from the network by disconnecting the network cable. What should the technician do NEXT according to incident response procedures?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Run a full antivirus scan on the workstation

Running an antivirus on an already-infected system may not guarantee removal of ransomware, and the infection may have already caused encryption; wiping and restoring from backup is more reliable.

B

Distractor review

Notify law enforcement and the company's legal department

While important in some contexts, this is not the immediate technical next step; the priority is to eradicate the threat and restore operations.

C

Best answer

Wipe the hard drive and restore from a known good backup

Wiping the drive and restoring from a clean backup ensures the ransomware is removed and data is recovered, following the eradication and recovery phases.

D

Distractor review

Collect forensic data for analysis

Forensic collection is often done before eradication if possible, but it is not always the immediate next step; many organizations prioritize recovery first.

Answer analysis

Why the other options are wrong

Understanding why incorrect options are tempting is as important as knowing the correct answer.

  • Run a full antivirus scan on the workstation

    Running an antivirus on an already-infected system may not guarantee removal of ransomware, and the infection may have already caused encryption; wiping and restoring from backup is more reliable.

  • Notify law enforcement and the company's legal department

    While important in some contexts, this is not the immediate technical next step; the priority is to eradicate the threat and restore operations.

  • Collect forensic data for analysis

    Forensic collection is often done before eradication if possible, but it is not always the immediate next step; many organizations prioritize recovery first.

Common exam trap

Common exam trap: answer the scenario, not the keyword

Candidates often choose 'Run a full antivirus scan' because it seems like a logical first technical step, but it's insufficient for ransomware.

Technical deep dive

How to think about this question

The core concept being tested here is the incident response process, specifically the eradication and recovery phases when dealing with a ransomware infection. After containment (isolating the machine), the most effective and reliable next step for ransomware is to completely eradicate the threat by wiping the infected system's hard drive. Ransomware often encrypts data and can embed itself deeply, making simple antivirus scans unreliable for complete removal. A full wipe ensures that all malicious code and encrypted data are removed, providing a clean slate. Following the wipe, the system is then restored from a known good backup, which is a copy of the data taken before the infection occurred. This two-step process guarantees that the system is free of malware and that the user's data is recovered to its pre-infection state, minimizing data loss and ensuring operational continuity. This approach directly addresses the primary goal of incident response: to return systems to normal operation securely and efficiently. This method differs significantly from merely running an antivirus scan, which might miss sophisticated ransomware or fail to decrypt already-encrypted files. While collecting forensic data (Option D) is a valid step in some incident response frameworks, especially for high-value targets or when a detailed post-mortem is required, it often takes a backseat to immediate eradication and recovery, particularly in a business environment where downtime is costly. Many organizations prioritize getting the user back to work quickly and securely. Notifying external parties like law enforcement (Option B) is a procedural step that typically occurs after the immediate technical threat has been neutralized or in parallel, but it is not the direct technical action to resolve the infection itself. The sequence of containment, eradication, and recovery is critical for effective incident response.

KKey Concepts to Remember

  • Wiping the drive ensures complete ransomware eradication.
  • Restoring from a known good backup recovers unencrypted data.
  • This process follows the eradication and recovery phases of incident response.
  • Antivirus scans are often ineffective against active ransomware encryption.

TExam Day Tips

  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Key takeaway

Wiping the drive ensures complete ransomware eradication.

Related practice questions

Related 220-1102 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

Question 1

A change advisory board (CAB) approved a standard change to update antivirus definitions on all servers. The technician completes the update on a file server and verifies the server is functioning normally. According to change management best practices, what documentation should the technician complete?

Question 2

A company's change management policy requires all server changes to be approved by the Change Advisory Board (CAB). A technician discovers that a critical database server's operating system needs a security patch to comply with a new regulatory requirement that takes effect in one week. The patch has a known risk of causing service downtime. The next scheduled CAB meeting is in two weeks. What should the technician do FIRST?

Question 3

A company is implementing a bring-your-own-device (BYOD) policy and needs to ensure that corporate data on employee mobile devices is protected. Which of the following is the MOST important technical control to implement?

Question 4

A company requires employees to present both a smart card and a PIN to log into their workstations. Which authentication principle is being implemented?

Question 5

A company requires all Windows 10 workstations to be able to join an Active Directory domain. Which edition of Windows 10 must be installed on these workstations?

Question 6

A company wants to allow employees to securely access internal resources from home via the internet. Which method provides the highest level of security for remote desktop connections?

Practice this exam

Start a free 220-1102 practice session

Short sessions build daily habit. Longer sessions build exam-day stamina. Try a timed session to simulate real conditions.

FAQ

Questions learners often ask

What does this 220-1102 question test?

Wiping the drive ensures complete ransomware eradication.

What is the correct answer to this question?

The correct answer is: Wipe the hard drive and restore from a known good backup — After containment, the next step in the incident response process is eradication and recovery. In the case of ransomware, eradication typically involves wiping the system and restoring from a clean backup. Notifying law enforcement may be required for some industries but is not the immediate next step. Running antivirus on an infected system may not fully remove ransomware and could risk further damage. Collecting forensic data is important but usually done before wiping; however, the standard first step after containment is to eradicate the malware and recover the system.

What should I do if I get this 220-1102 question wrong?

Review wiping the drive ensures complete ransomware eradication., then practise related 220-1102 questions on the same topic to reinforce the concept.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Keep practising

More 220-1102 practice questions

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.