nerdexam
CompTIACompTIA

220-1202 · Question #85

220-1202 Question #85: Real Exam Question with Answer & Explanation

The correct answer is A: Disconnect the computer from the network. The technician should disconnect the computer from the network (Option A) first to prevent any further spread of the infection or data loss. Once the machine is isolated from the network, the technician can safely investigate the malware without risking infection to other systems

Submitted by salim_om· Mar 30, 2026

Question

A user's PC is performing slowly after the user clicked on a suspicious email attachment. The technician notices that a single process is taking 100% of RAM, CPU, and network resources. Which of the following should the technician do first?

Options

  • ADisconnect the computer from the network
  • BRun an antivirus scan
  • CReboot the computer
  • DEducate the user about cybersecurity best practices

Explanation

The technician should disconnect the computer from the network (Option A) first to prevent any further spread of the infection or data loss. Once the machine is isolated from the network, the technician can safely investigate the malware without risking infection to other systems.

Topics

#Malware#Incident Response#Network Disconnection

Community Discussion

No community discussion yet for this question.

Full 220-1202 PracticeBrowse All 220-1202 Questions