312-39 Incident Response Practice Question
Which TWO actions should be taken immediately upon identifying an active malware infection on a workstation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the user account associated
Isolating the host prevents spreading; disconnecting the network allows for forensics without alerting the malware to changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reboot the machine
Why it's wrong here
Rebooting risks evidence loss.
- ✓
Disable the user account associated
Why this is correct
Prevents the attacker from continuing to use the compromised creds.
- ✗
Delete the malware file
Why it's wrong here
Must be preserved for evidence.
- ✓
Isolate the host from the network
Why this is correct
Necessary for containment.
- ✗
Update antivirus definitions
Why it's wrong here
Not an immediate containment action.
About these practice questions
Courseiva writes every 312-39 question from scratch — 201 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official EC-Council exam blueprint
This 312-39 practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 312-39 exam.