220-1102 exam dumps

220-1102 practice question 444 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 444

Single answerZero-day attack

A help desk technician receives several reports that users who visit a legitimate vendor website are suddenly seeing command prompt windows flash briefly, followed by abnormal outbound traffic from their PCs. The antivirus console shows no detections, and the vendor confirms its site was recently compromised. Security staff suspect a zero-day attack delivered through the users' web browsers. Which action should the technician take FIRST to reduce further impact while the incident is investigated?

  1. A

    Disconnect affected systems from the network and escalate the incident according to the organization's security procedures

  2. B

    Clear the browser cache and cookies on each affected workstation, then have users reconnect and test the website again

  3. C

    Run defragmentation and disk cleanup tools to remove malicious files that antivirus did not detect

  4. D

    Add the vendor's website to the browser's trusted sites list so its content is less likely to be blocked incorrectly

Show answer and explanation

Correct answer: A

Explanation

A zero-day attack exploits a vulnerability before a patch or reliable signature-based detection is widely available. In a scenario where legitimate websites are being used to deliver malicious code and antivirus has no detection yet, the best first step is containment: isolate affected endpoints and follow the organization's incident response process. This aligns with common security best practices from sources such as NIST incident handling guidance, which emphasizes containment before eradication and recovery. For A+ Core 2 purposes, technicians should recognize that when a system shows signs of compromise from a suspected zero-day, they should avoid actions that increase exposure or modify evidence unnecessarily. The practical response is to disconnect, document, and escalate.

  • A. Correct.

    Correct. With a suspected zero-day attack, the immediate priority is containment. Disconnecting impacted systems from the network helps stop command-and-control communication, data exfiltration, and lateral movement while the issue is analyzed. Escalating through established incident response procedures is also appropriate because zero-day threats often require coordinated investigation, isolation, and remediation beyond routine desktop support.

  • B. Incorrect.

    Incorrect. Clearing cache and cookies may remove some temporary browser data, but it does not address an active compromise or prevent continued malicious network activity. Reconnecting users and retesting the compromised site could expose systems further. This is a common misconception because browser cleanup is useful for troubleshooting normal website issues, but not as a first response to a likely malware incident.

  • C. Incorrect.

    Incorrect. Defragmentation and disk cleanup are maintenance tasks, not incident response controls. They do not contain a zero-day attack and may even alter forensic evidence that security personnel may need for investigation. A candidate might choose this option if they confuse general system cleanup with malware remediation.

  • D. Incorrect.

    Incorrect. Adding a compromised website to the trusted sites list would reduce browser security restrictions for that site and could increase risk. This directly conflicts with the goal of limiting exposure during a suspected exploit. The misconception here is assuming access problems are due to overblocking rather than an actual compromise.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam