nerdexam
CompTIA

220-1002 · Question #394

Ann, a technician, is dispatched to a corporate customer that has reported a malware infection. Upon arrival, Ann notices the system is shut off, and she is able to start the computer without…

The correct answer is A. Report the incident to the appropriate contact. In a corporate environment, the correct incident response procedure is to report the malware incident to the appropriate contact (e.g., a manager or IT security team) before taking remediation action. This ensures proper chain of custody, documentation, and authorization…

Hardware and network troubleshooting

Question

Ann, a technician, is dispatched to a corporate customer that has reported a malware infection. Upon arrival, Ann notices the system is shut off, and she is able to start the computer without incident. Ann also notices numerous pop-ups appear when the web browser is opened. Which of the following should Ann do NEXT?

Options

  • AReport the incident to the appropriate contact
  • BClear the system logs and browser history
  • CTake a screenshot of the pop-ups
  • DAdvise the customer to use the browser in private mode

How the community answered

(69 responses)
  • A
    71% (49)
  • B
    17% (12)
  • C
    7% (5)
  • D
    4% (3)

Explanation

In a corporate environment, the correct incident response procedure is to report the malware incident to the appropriate contact (e.g., a manager or IT security team) before taking remediation action. This ensures proper chain of custody, documentation, and authorization. Clearing logs or browser history (option B) would destroy forensic evidence. Working in private mode (option D) does not address the infection. While taking a screenshot (option C) is useful for documentation, reporting to the appropriate contact takes priority as it initiates the formal incident response process.

Topics

#malware incident#escalation procedures#pop-ups#incident response

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice