220-1102 exam dumps

220-1102 practice question 455 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 455

Single answerNon-compliant systems

A technician is assisting with a security audit at a medical office. One Windows workstation that stores patient files is missing recent security patches, has outdated antivirus signatures, and does not meet the company's documented security baseline. The office manager says the computer is needed for daily scheduling and cannot be shut down for long. According to best practices for handling a non-compliant system, what should the technician do FIRST?

  1. A

    Disconnect the workstation from the network or move it to a quarantine/remediation network

  2. B

    Leave the workstation in production and schedule updates for the next monthly maintenance window

  3. C

    Wipe the workstation immediately and reimage it before notifying anyone

  4. D

    Disable User Account Control so the updates can install with fewer prompts

Show answer and explanation

Correct answer: A

Explanation

For A+ Core 2, a non-compliant system is one that does not meet organizational security policy, regulatory requirements, or the defined security baseline. In a real-world environment, the correct first action is usually containment: remove the system from the production network or place it in a restricted remediation VLAN/network so it cannot continue to expose the environment. After that, the technician should follow company procedures for documentation, escalation, patching, antivirus updates, validation, and return to service. This approach aligns with common security best practices such as least privilege, defense in depth, and incident containment. In regulated environments like healthcare, protecting sensitive information and following organizational policy are especially important.

  • A. Correct.

    Correct. A non-compliant system that is missing patches and has outdated antimalware protection poses an immediate security risk, especially in an environment handling sensitive data such as patient records. The first priority is containment: isolate the device from production resources to reduce the chance of malware infection, lateral movement, or data exposure. After isolation, the issue can be documented, escalated according to policy, and remediated.

  • B. Incorrect.

    Incorrect. Waiting until the next maintenance window leaves a known non-compliant and vulnerable system connected to the production network. This increases risk and does not align with standard incident response and security best practices, which emphasize containment of systems that fall outside the required baseline.

  • C. Incorrect.

    Incorrect. Reimaging may be appropriate in some cases, but it is not the first step here. The system should first be contained and the issue handled according to organizational policy. Immediately wiping the machine could disrupt business operations, destroy evidence if compromise is suspected, and bypass required approval or change-management procedures.

  • D. Incorrect.

    Incorrect. Disabling User Account Control reduces security and does not address the underlying compliance issues. UAC helps limit unauthorized system changes. Lowering security controls on a non-compliant system would make the situation worse, not better.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam