nerdexam
CompTIA

220-802 · Question #258

A technician discovers a networked computer has been infected with a zero day virus. Which of the following is the FIRST thing that should be done to the workstation?

The correct answer is C. Unplug it from the network. The immediate first step when a zero-day virus is discovered on a networked machine is to isolate it by unplugging it from the network. This prevents the malware from spreading to other systems, communicating with a command-and-control server, or causing further damage…

Hardware and network troubleshooting

Question

A technician discovers a networked computer has been infected with a zero day virus. Which of the following is the FIRST thing that should be done to the workstation?

Options

  • ADocument the symptoms of the virus.
  • BTurn off the computer using the power switch.
  • CUnplug it from the network.
  • DRun an antivirus update and then a full scan.

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    6% (3)
  • C
    79% (41)
  • D
    13% (7)

Explanation

The immediate first step when a zero-day virus is discovered on a networked machine is to isolate it by unplugging it from the network. This prevents the malware from spreading to other systems, communicating with a command-and-control server, or causing further damage. Documenting symptoms, running antivirus scans, and other remediation steps all come after the machine has been isolated. Turning off the computer via the power switch is secondary and may even destroy volatile forensic evidence.

Topics

#malware response#zero day#network isolation#incident response

Community Discussion

No community discussion yet for this question.

Full 220-802 Practice