220-1102 exam dumps

220-1102 practice question 509 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 509

Single answerEndpoint security software

A small accounting firm uses centrally managed endpoint protection on all Windows 11 laptops. One employee reports that after opening an email attachment, the laptop became slow and several files now have unfamiliar extensions. The endpoint security console shows repeated ransomware detections on that device, but the user is still connected to the corporate Wi-Fi and shared drives. What should the technician do FIRST to follow endpoint security best practices and limit further damage?

  1. A

    Isolate the affected laptop from the network using the endpoint security console or by disconnecting it from Wi-Fi

  2. B

    Uninstall the endpoint protection agent so it does not interfere with file recovery

  3. C

    Have the user reboot several times until the ransomware process stops

  4. D

    Map the shared drive on another computer to confirm whether the encrypted files are accessible

Show answer and explanation

Correct answer: A

Explanation

This question tests practical use of endpoint security software during a live security incident. In a ransomware scenario, the technician should first contain the affected endpoint to reduce lateral movement and prevent additional encryption of shared resources. Endpoint security best practices emphasize identifying, isolating, and then remediating infected systems. This aligns with common incident response guidance from sources such as NIST's Computer Security Incident Handling Guide (SP 800-61), which prioritizes containment early in the response process. In real environments, centrally managed endpoint protection platforms often provide host isolation, alerting, quarantine, and remediation features. After isolation, the technician would typically preserve evidence as required by policy, notify the security team, review alerts and logs, run approved remediation steps, and assess whether restoration from clean backups is necessary.

  • A. Correct.

    Correct. The first priority in a suspected ransomware incident is containment. Isolating the endpoint from the network helps prevent the malware from reaching additional systems, network shares, and backup repositories. Many modern endpoint detection and response (EDR) or endpoint protection platforms include a host isolation feature specifically for this purpose. Disconnecting Wi-Fi or removing network access is an appropriate immediate step if console-based isolation is not available.

  • B. Incorrect.

    Incorrect. Removing the endpoint protection agent weakens defenses and can eliminate telemetry, quarantine capability, and centralized response tools. A common misconception is that security software should be removed if malware is active, but best practice is to use the tool's containment and remediation functions rather than disable or uninstall it during an active incident.

  • C. Incorrect.

    Incorrect. Rebooting may not stop ransomware and can sometimes trigger additional malicious activity at startup or interfere with forensic evidence collection. While a reboot is sometimes part of guided remediation, it is not the first action when the system is still connected to internal resources and may be spreading damage.

  • D. Incorrect.

    Incorrect. Accessing the shared drive from another computer does not contain the incident and may expose another endpoint or confirm ongoing damage without reducing risk. The immediate goal is to stop propagation, not to verify the extent of encryption before containment.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam