220-1102 exam dumps

220-1102 practice question 523 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 523

Single answerDrilling

A help desk technician is reviewing endpoint alerts and notices repeated signs that a user opened a phishing email, downloaded a malicious attachment, and then made an outbound connection to an unknown host. The security team wants to understand exactly how the attack progressed on this one workstation so they can decide whether other systems are affected. Which incident response activity should the technician perform NEXT to gather detailed information about the attacker’s actions on the compromised system?

  1. A

    Quarantine the workstation from the network to stop further communication

  2. B

    Perform drilling to trace the event sequence and examine system details related to the compromise

  3. C

    Apply all pending operating system patches to remove the vulnerability

  4. D

    Restore the user profile from the last known good backup

Show answer and explanation

Correct answer: B

Explanation

The best answer is to perform drilling because the scenario is asking for deeper investigation into a specific incident on a specific endpoint. In A+ Core 2 security operations and malware response concepts, technicians are expected to distinguish between investigation, containment, remediation, and recovery. Drilling is used to follow the trail of an alert into more detailed logs, endpoint telemetry, process history, and related indicators so the team can reconstruct the timeline and determine scope. By contrast, quarantining is containment, patching is remediation, and restoring from backup is recovery. This aligns with common incident response best practices, which emphasize understanding the nature and extent of an incident before making changes that could remove evidence.

  • A. Incorrect.

    Quarantining the workstation is often an important containment step in incident response, and a candidate might choose it because it limits additional damage. However, the question specifically asks which activity should be performed next to gather detailed information about how the attack progressed on the affected system. Quarantine focuses on containment, not on the investigative process of analyzing the sequence and depth of the incident.

  • B. Correct.

    Correct. Drilling means digging deeper into alerts, logs, and related endpoint details to trace what happened, how it happened, and what the attacker did after initial compromise. In this scenario, the security team wants detailed insight into the progression of the attack on a single workstation, which is exactly the purpose of drilling during security analysis.

  • C. Incorrect.

    Applying patches is a remediation activity, not an investigative one. It may be appropriate later, but patching before understanding the incident can alter evidence and does not help reconstruct the attacker’s actions on the compromised endpoint.

  • D. Incorrect.

    Restoring from backup is a recovery action. A technician might consider it because it can return the system to a usable state, but it does not help determine the attack path or scope. Restoring too early can also destroy useful forensic evidence needed for analysis.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam