nerdexam
CompTIA

220-1102 · Question #160

A technician received a call stating that all files in a user's documents folder appear to be changed, and each of the files now has a .lock file extension. Which of the following actions is the…

The correct answer is D. Disconnect the machine from the network. The presence of '.lock' file extensions on all documents strongly indicates a ransomware attack, requiring immediate network disconnection to prevent further encryption or spread.

Security

Question

A technician received a call stating that all files in a user's documents folder appear to be changed, and each of the files now has a .lock file extension. Which of the following actions is the FIRST step the technician should take?

Options

  • ARun a live disk clone.
  • BRun a full antivirus scan.
  • CUse a batch file to rename the files.
  • DDisconnect the machine from the network.

How the community answered

(33 responses)
  • A
    9% (3)
  • B
    6% (2)
  • C
    3% (1)
  • D
    82% (27)

Why each option

The presence of '.lock' file extensions on all documents strongly indicates a ransomware attack, requiring immediate network disconnection to prevent further encryption or spread.

ARun a live disk clone.

Running a live disk clone is a good step for forensic analysis or recovery, but it should be done after isolating the threat to prevent further damage or spread, not as the very first immediate action.

BRun a full antivirus scan.

Running a full antivirus scan is an important step, but it should happen after the machine is isolated from the network to prevent the malware from potentially communicating with command and control servers or spreading further during the scan.

CUse a batch file to rename the files.

Using a batch file to rename the files would be futile and potentially damaging, as the files are encrypted, not just renamed; renaming them would not decrypt them and might complicate recovery efforts.

DDisconnect the machine from the network.Correct

The '.lock' file extension on all documents is a classic sign of a ransomware infection, which encrypts files and often attempts to spread across the network. Disconnecting the machine from the network immediately is the crucial first step to prevent further encryption, stop potential spread to other systems, and isolate the threat.

Concept tested: Incident response, ransomware mitigation, network security

Source: learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/investigate-respond-alerts-microsoft-defender-for-endpoint?view=o365-worldwide#responding-to-an-incident

Topics

#Ransomware#Incident Response#Containment#Malware

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice