nerdexam
CompTIA

220-1002 · Question #188

A technician receives a phone call regarding ransomware that has been detected on a PC in a remote office. Which of the following steps should the technician take FIRST?

The correct answer is A. Disconnect the PC from the network. The very first step in responding to a ransomware infection is to immediately disconnect the affected PC from the network. Ransomware actively attempts to spread laterally across the network, encrypting shared drives and other connected systems. Isolation (containment) stops…

Hardware and network troubleshooting

Question

A technician receives a phone call regarding ransomware that has been detected on a PC in a remote office. Which of the following steps should the technician take FIRST?

Options

  • ADisconnect the PC from the network
  • BPerform an antivirus scan
  • CRun a backup and restore
  • DEducate the end user

How the community answered

(46 responses)
  • A
    80% (37)
  • B
    2% (1)
  • C
    11% (5)
  • D
    7% (3)

Explanation

The very first step in responding to a ransomware infection is to immediately disconnect the affected PC from the network. Ransomware actively attempts to spread laterally across the network, encrypting shared drives and other connected systems. Isolation (containment) stops the spread before any remediation begins. This is the first phase of incident response: Identify, then Contain. Running an antivirus scan, restoring from backup, or educating the user are all appropriate later steps, but none of them prevent the ransomware from propagating to other machines while the PC remains connected. Network isolation is the single most time-critical action.

Topics

#ransomware#network isolation#incident response#malware containment

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice