220-1002 · Question #188
A technician receives a phone call regarding ransomware that has been detected on a PC in a remote office. Which of the following steps should the technician take FIRST?
The correct answer is A. Disconnect the PC from the network. The very first step in responding to a ransomware infection is to immediately disconnect the affected PC from the network. Ransomware actively attempts to spread laterally across the network, encrypting shared drives and other connected systems. Isolation (containment) stops…
Question
A technician receives a phone call regarding ransomware that has been detected on a PC in a remote office. Which of the following steps should the technician take FIRST?
Options
- ADisconnect the PC from the network
- BPerform an antivirus scan
- CRun a backup and restore
- DEducate the end user
How the community answered
(46 responses)- A80% (37)
- B2% (1)
- C11% (5)
- D7% (3)
Explanation
The very first step in responding to a ransomware infection is to immediately disconnect the affected PC from the network. Ransomware actively attempts to spread laterally across the network, encrypting shared drives and other connected systems. Isolation (containment) stops the spread before any remediation begins. This is the first phase of incident response: Identify, then Contain. Running an antivirus scan, restoring from backup, or educating the user are all appropriate later steps, but none of them prevent the ransomware from propagating to other machines while the PC remains connected. Network isolation is the single most time-critical action.
Topics
Community Discussion
No community discussion yet for this question.