nerdexam
CompTIA

220-1102 · Question #381

A technician sees a file that is requesting payment to a cryptocurrency address. Which of the following should the technician do first?

The correct answer is A. Quarantine the computer. A file requesting cryptocurrency payment indicates a ransomware infection, and the first step is to isolate the infected system to prevent further spread.

Security

Question

A technician sees a file that is requesting payment to a cryptocurrency address. Which of the following should the technician do first?

Options

  • AQuarantine the computer.
  • BDisable System Restore.
  • CUpdate the antivirus software definitions.
  • DBoot to safe mode.

How the community answered

(25 responses)
  • A
    76% (19)
  • B
    4% (1)
  • C
    4% (1)
  • D
    16% (4)

Why each option

A file requesting cryptocurrency payment indicates a ransomware infection, and the first step is to isolate the infected system to prevent further spread.

AQuarantine the computer.Correct

Quarantining the computer immediately isolates it from the network, preventing the ransomware from encrypting shared drives, spreading to other systems, or exfiltrating data, thus containing the threat. This is a critical initial response to a confirmed malware infection like ransomware to limit damage.

BDisable System Restore.

Disabling System Restore is a destructive action that removes potential recovery points and should not be the first step, especially before understanding the full scope of the infection.

CUpdate the antivirus software definitions.

Updating antivirus definitions is a proactive measure for prevention or a later step in remediation; it does not address the immediate threat of an active, known infection which requires containment.

DBoot to safe mode.

Booting to safe mode can be part of remediation to remove malware, but it does not address the immediate need to prevent the ransomware from spreading or continuing its activity on the network.

Concept tested: Incident response - malware containment

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/respond-machine-alerts?view=o365-worldwide

Topics

#Ransomware#Malware removal#Incident response#Security procedures

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice