220-1102 exam dumps

220-1102 practice question 418 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 418

Single answerEndpoint detection and response (EDR)

A technician receives an alert from the company's endpoint detection and response (EDR) platform indicating that a finance user's laptop started PowerShell from Microsoft Word and then attempted to contact a known malicious IP address. The user says they opened an email attachment just before the alert appeared and is still connected to the corporate network. What should the technician do FIRST to best limit the impact while preserving the ability to investigate?

  1. A

    Use the EDR platform to isolate the laptop from the network

  2. B

    Uninstall Microsoft Word to prevent the document from running again

  3. C

    Delete the suspicious email from the user's mailbox and close the ticket

  4. D

    Reboot the laptop so the malicious process stops immediately

Show answer and explanation

Correct answer: A

Explanation

This question tests practical use of EDR in an active security event. In a likely phishing-to-malware scenario, the highest-priority action is containment. Modern EDR platforms commonly provide endpoint isolation specifically for this purpose: limiting network communication while preserving management access and telemetry collection. That supports standard incident response principles of containment before eradication and recovery. Behavioral indicators such as Word launching PowerShell and contacting a known malicious IP strongly suggest malicious execution rather than a benign false positive. Security best practices from common incident response guidance, including NIST incident handling principles, emphasize quickly containing affected systems to reduce spread and preserve evidence for investigation.

  • A. Correct.

    Correct. Isolating the endpoint through the EDR platform is the best first response in this scenario. EDR tools are designed to detect suspicious behavior such as Office spawning PowerShell and outbound communication to malicious infrastructure. Network isolation helps contain the threat quickly, preventing lateral movement or additional command-and-control traffic, while still allowing the security team to collect telemetry, review process trees, and perform remote investigation.

  • B. Incorrect.

    Incorrect. Removing Word does not address the immediate threat and is not an appropriate first containment action. The suspicious process may already be running, persistence may already be established, and the endpoint could still be communicating with malicious systems. This option also disrupts business operations without containing the active incident.

  • C. Incorrect.

    Incorrect. Deleting the email may remove one copy of the phishing message, but it does not contain the already-compromised endpoint. The malicious script or payload may already be executing. Closing the ticket is also inappropriate because the EDR alert indicates likely malicious activity that requires containment and investigation.

  • D. Incorrect.

    Incorrect. Rebooting may interrupt some malicious activity, but it is not the best first step. A reboot can destroy volatile evidence in memory, disrupt forensic analysis, and may not prevent the malware from restarting if persistence has been established. Best practice is to contain first, then investigate and remediate in a controlled manner.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam