nerdexam
CompTIA

220-1002 · Question #292

A user reports personal files have been renamed and are undecipherable. Images have been to the user's folder that request payment to unlock the files. The technician has quarantined the infected…

The correct answer is B. Remove the malware and recover the files from a backup. This is a ransomware attack. Ransomware uses strong asymmetric encryption to lock files, and the decryption key is held by the attacker. The only reliable recovery method is to remove the malware and restore the files from a clean, pre-infection backup. A clean OS installation…

Hardware and network troubleshooting

Question

A user reports personal files have been renamed and are undecipherable. Images have been to the user's folder that request payment to unlock the files. The technician has quarantined the infected system and disabled System Restore. Which of the following should the technician do to unlock the user's files?

Options

  • APerform a clean installation of Windows
  • BRemove the malware and recover the files from a backup
  • CInitialize and repartition the hard drive to recover the files
  • DRun safe mode to decrypt the user's files

How the community answered

(66 responses)
  • A
    5% (3)
  • B
    80% (53)
  • C
    3% (2)
  • D
    12% (8)

Explanation

This is a ransomware attack. Ransomware uses strong asymmetric encryption to lock files, and the decryption key is held by the attacker. The only reliable recovery method is to remove the malware and restore the files from a clean, pre-infection backup. A clean OS installation (A) does not recover encrypted user files. Initializing and repartitioning the drive (C) destroys all data. Booting into safe mode (D) does not provide decryption capability - the encryption key is not stored locally.

Topics

#ransomware#malware remediation#backup recovery#malware removal

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice