CEH Practice Question: Malware, Social Engineering and Network Attacks
A user reports that their computer is infected with ransomware. Which of the following is the BEST immediate action for the security team to take?
⚠ Common exam trap
Many candidates mistakenly prioritize running an antivirus scan or restoring from backup as the immediate step. However, the CEH exam emphasizes containment first to prevent lateral movement and further damage. Disconnecting from the network is critical to stop the spread of ransomware.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the computer from the network
Disconnecting the computer from the network is the best immediate action because it isolates the ransomware, preventing it from spreading laterally to other systems via SMB, RDP, or mapped drives. This containment step stops the encryption of additional network shares and halts any command-and-control (C2) communication the ransomware might be using to exfiltrate data or receive encryption keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disconnect the computer from the network
Why this is correct
Disconnecting the computer from the network is the immediate and most critical first step in containing a ransomware infection. This action severs the malware's ability to communicate with command-and-control (C2) servers, preventing further encryption key exchange, data exfiltration, or the reception of additional malicious instructions. Crucially, it also stops the ransomware from spreading laterally across the network to other systems or encrypting shared network drives, thereby limiting the scope of the compromise and preventing further damage.
- ✗
Pay the ransom to regain access
Why it's wrong here
Paying the ransom is strongly discouraged as it does not guarantee the successful decryption of files and often funds future criminal activities, perpetuating the ransomware ecosystem. Furthermore, organizations that pay the ransom may be marked as willing targets for subsequent attacks, making them more vulnerable in the long term. It is a last resort that should only be considered after all other recovery options have been exhausted and a thorough risk assessment has been performed, often with legal and cybersecurity expert consultation.
- ✗
Run a full antivirus scan
Why it's wrong here
Running a full antivirus scan immediately upon discovering ransomware, without prior network isolation, can be counterproductive and even dangerous. Modern ransomware variants are often designed to detect security tools and may react by deleting encryption keys, accelerating the encryption process, or triggering further destructive actions upon detection. Moreover, if the malware has rootkit capabilities or exploits zero-day vulnerabilities, the antivirus scan might fail to detect it, providing a false sense of security while the threat remains active and connected.
- ✗
Restore the system from a recent backup
Why it's wrong here
Restoring the system from a recent backup, while a crucial recovery step, should only occur after the ransomware threat has been fully contained and eradicated from the affected system and network. Attempting to restore prematurely risks immediate reinfection if the original vulnerability exploited by the ransomware has not been identified and patched, or if remnants of the malware persist. A thorough forensic analysis is essential to understand the attack vector, ensure complete removal, and verify the integrity of the backup before initiating recovery.
Go deeper
Related to this question
About these practice questions
One of 870 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.