220-1002 · Question #626
Many of the files in a user's network folder have a new file extension and are inaccessible. After some troubleshooting, a technician discovers a text document that states the files were…
The correct answer is D. Disconnect the computer from the network. NOTE: The listed correct answer (D) does not align with the question's goal of recovering the files. This scenario describes a ransomware attack - files have been encrypted by malware and a ransom is demanded for decryption. Disconnecting from the network (D) is the correct…
Question
Many of the files in a user's network folder have a new file extension and are inaccessible. After some troubleshooting, a technician discovers a text document that states the files were intentionally encrypted, and a large sum of money is required to decrypt them. Which of the following should the technician do to recover the files?
Options
- ARestore the network folder from a backup.
- BPerform a System Restore on the computer.
- CUpdate the malware scanner and run a full scan.
- DDisconnect the computer from the network.
How the community answered
(42 responses)- A5% (2)
- B17% (7)
- C10% (4)
- D69% (29)
Explanation
NOTE: The listed correct answer (D) does not align with the question's goal of recovering the files. This scenario describes a ransomware attack - files have been encrypted by malware and a ransom is demanded for decryption. Disconnecting from the network (D) is the correct FIRST response to contain the spread, but it does not recover the files. To actually recover the encrypted files, the technician should restore the network folder from a clean backup (A), which is the most reliable recovery method for ransomware. Running an antivirus scan (C) removes the malware but cannot decrypt already-encrypted files. System Restore (B) addresses OS files, not user data in a network folder. For CompTIA A+ exam purposes, the answer to 'recover the files' is A (restore from backup), while D (disconnect from network) is the correct containment step.
Topics
Community Discussion
No community discussion yet for this question.