Courseiva
Malware, Social Engineering and Network AttackseasyMultiple ChoiceObjective-mapped

CEH Practice Question: Malware, Social Engineering and Network Attacks

A user reports that their computer is infected with ransomware. Which of the following is the BEST immediate action for the security team to take?

⚠ Common exam trap

Many candidates mistakenly prioritize running an antivirus scan or restoring from backup as the immediate step. However, the CEH exam emphasizes containment first to prevent lateral movement and further damage. Disconnecting from the network is critical to stop the spread of ransomware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disconnect the computer from the network

Disconnecting the computer from the network is the best immediate action because it isolates the ransomware, preventing it from spreading laterally to other systems via SMB, RDP, or mapped drives. This containment step stops the encryption of additional network shares and halts any command-and-control (C2) communication the ransomware might be using to exfiltrate data or receive encryption keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Disconnect the computer from the network

    Why this is correct

    Disconnecting the computer from the network is the immediate and most critical first step in containing a ransomware infection. This action severs the malware's ability to communicate with command-and-control (C2) servers, preventing further encryption key exchange, data exfiltration, or the reception of additional malicious instructions. Crucially, it also stops the ransomware from spreading laterally across the network to other systems or encrypting shared network drives, thereby limiting the scope of the compromise and preventing further damage.

  • Pay the ransom to regain access

    Why it's wrong here

    Paying the ransom is strongly discouraged as it does not guarantee the successful decryption of files and often funds future criminal activities, perpetuating the ransomware ecosystem. Furthermore, organizations that pay the ransom may be marked as willing targets for subsequent attacks, making them more vulnerable in the long term. It is a last resort that should only be considered after all other recovery options have been exhausted and a thorough risk assessment has been performed, often with legal and cybersecurity expert consultation.

  • Run a full antivirus scan

    Why it's wrong here

    Running a full antivirus scan immediately upon discovering ransomware, without prior network isolation, can be counterproductive and even dangerous. Modern ransomware variants are often designed to detect security tools and may react by deleting encryption keys, accelerating the encryption process, or triggering further destructive actions upon detection. Moreover, if the malware has rootkit capabilities or exploits zero-day vulnerabilities, the antivirus scan might fail to detect it, providing a false sense of security while the threat remains active and connected.

  • Restore the system from a recent backup

    Why it's wrong here

    Restoring the system from a recent backup, while a crucial recovery step, should only occur after the ransomware threat has been fully contained and eradicated from the affected system and network. Attempting to restore prematurely risks immediate reinfection if the original vulnerability exploited by the ransomware has not been identified and patched, or if remnants of the malware persist. A thorough forensic analysis is essential to understand the attack vector, ensure complete removal, and verify the integrity of the backup before initiating recovery.

About these practice questions

One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.