hardMultiple Choice
FC0-U71 Practice Question: After a ransomware attack, which step should be…
After a ransomware attack, which step should be taken FIRST in the incident response process?
⚠ Common exam trap
CompTIA often tests the misconception that the first step should be to restore from backups or notify authorities, but the correct first step is always containment to stop the spread of the attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect affected systems from network
The first step in incident response after a ransomware attack is to contain the threat by disconnecting affected systems from the network. This prevents the ransomware from encrypting additional files on other systems and stops lateral movement, which is critical because ransomware often uses network shares and SMB protocols to spread. Immediate isolation preserves forensic evidence and limits the scope of the incident before any other actions are taken.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify law enforcement
Why it's wrong here
Notification follows containment and internal escalation; evidence must be preserved and the breach scoped first, and legal or regulatory timelines are met after the threat is stopped. Law enforcement engagement is appropriate once containment is underway and forensic details are established, not as the opening action.
- ✓
Disconnect affected systems from network
Why this is correct
Disconnecting affected systems from the network immediately contains the spread, satisfying the stem's "FIRST" constraint in the incident response process. Ransomware propagates laterally via SMB, RDP and shared drives, so isolating hosts halts encryption before eradication or recovery begins. Preservation and notification follow containment, not precede it.
- ✗
Restore from backup
Why it's wrong here
Restoring from backup happens during recovery, after containment and eradication, so reinfection or re-encryption can occur while the threat remains active. Restoration is the right action once the malware is removed and systems are verified clean, but not before the incident is contained.
- ✗
Pay the ransom
Why it's wrong here
Paying the ransom funds criminal activity, does not guarantee decryption, and destroys containment options. Containment and eradication come first. Payment is tempting under time pressure to restore operations quickly, and it would only be considered after legal, regulatory and law-enforcement consultation, never as the opening step.
Go deeper
Related to this question
About these practice questions
This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.