220-1102 exam dumps

220-1102 practice question 420 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 420

Single answerExtended detection and response (XDR)

A small business uses an extended detection and response (XDR) platform that collects telemetry from endpoints, email, firewall logs, and cloud applications. A technician receives a high-severity XDR alert showing that a user opened a malicious email attachment, the endpoint spawned a suspicious PowerShell process, and the same host attempted connections to a known command-and-control domain. The technician needs to take the BEST immediate action to limit further damage while preserving visibility for investigation. What should the technician do first?

  1. A

    Use the XDR platform to isolate the affected endpoint from the network

  2. B

    Delete the user's mailbox to prevent future phishing messages

  3. C

    Reimage the endpoint immediately without reviewing the alert details

  4. D

    Disable all outbound internet access at the firewall for the entire company

Show answer and explanation

Correct answer: A

Explanation

XDR improves detection and response by correlating activity across multiple control points, such as endpoints, email, network, identity, and cloud services. In this scenario, the correlated indicators show a likely active compromise: malicious email attachment execution, suspicious PowerShell activity, and outbound communication to a known command-and-control domain. The best immediate action is targeted containment by isolating the affected host. This follows common incident response best practices of containment before eradication and recovery, and it aligns with how XDR platforms are commonly used in practice: identify related events quickly, reduce dwell time, and contain the affected asset without unnecessarily disrupting the entire environment. Guidance from major security vendors and frameworks such as NIST incident response recommendations supports prioritizing rapid containment of confirmed or likely compromised systems while preserving evidence for analysis.

  • A. Correct.

    Correct. One of the key practical benefits of XDR is that it correlates signals across multiple security layers and can often trigger or support a rapid containment action, such as host isolation. In this scenario, the platform has already linked email delivery, malicious process activity, and command-and-control traffic, which strongly suggests active compromise. Isolating the endpoint limits lateral movement and further outbound communication while preserving the system state and centralized alert data for investigation.

  • B. Incorrect.

    Incorrect. Deleting the user's mailbox is not the best immediate containment step for an actively compromised endpoint. It also risks removing evidence and does not stop the already infected system from continuing malicious activity. A user might choose this because the attack started with email, but XDR indicates the threat has progressed beyond delivery into execution and network communication.

  • C. Incorrect.

    Incorrect. Reimaging may eventually be appropriate if the device is confirmed compromised, but doing so immediately is not the best first action. It destroys volatile evidence and bypasses the containment and investigation capabilities that XDR is designed to support. A common misconception is that rebuilding a system is always the fastest fix, but incident response best practice is to contain first, then investigate and remediate.

  • D. Incorrect.

    Incorrect. Blocking all outbound internet access for the entire company is overly broad and would create major business disruption. XDR is intended to improve precision by correlating data and enabling targeted response. While network controls can be useful, the best immediate step here is to isolate the specific affected endpoint rather than apply a company-wide outage.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam