220-1102 Question 623
Single answerCommon symptomsA user reports that their Windows 11 laptop suddenly shows a ransom note after logging in. Most documents now have unfamiliar file extensions, and the user says they opened an attachment from an unknown sender earlier that morning. The PC is still connected to the company network. Which action should the technician take FIRST?
- A
Disconnect the laptop from the network immediately
- B
Run Disk Cleanup to remove temporary files and free space
- C
Restore the user's documents from a recent backup right away
- D
Install the latest Windows updates and reboot the laptop
Show answer and explanation
Correct answer: A
Explanation
This scenario tests recognition of a common malware symptom: unexpected ransom messages and files becoming inaccessible or renamed with unusual extensions. In A+ Core 2, candidates are expected to identify these symptoms and apply the correct first response. The best initial action is to isolate the device from the network to contain the threat. After containment, the technician would typically follow organizational procedures such as notifying security personnel, preserving evidence as required, removing the malware, and restoring data from known-good backups. This aligns with standard security best practices, including the general incident-response approach of identify, contain, eradicate, and recover, and with Microsoft and other vendor guidance to isolate ransomware-affected devices promptly.
- A. Correct.
Correct. A ransom note combined with encrypted files and suspicious extensions is a classic symptom of ransomware. The first priority is containment: disconnect the affected system from wired, wireless, VPN, or other network access to reduce the chance of lateral spread to file shares or other endpoints. CompTIA troubleshooting and incident-response best practices emphasize containing malware before remediation.
- B. Incorrect.
Incorrect. Disk Cleanup addresses storage-related performance issues, not active malware incidents. Choosing this option reflects a misunderstanding of the symptom. The problem is not low disk space; it is likely ransomware infection requiring immediate isolation.
- C. Incorrect.
Incorrect. Restoring files may be appropriate later, but not as the first step while the system is still connected to the network and the infection may still be active. Restoring too soon can result in re-encryption of recovered data or continued spread to shared resources.
- D. Incorrect.
Incorrect. Applying updates is a good security practice, but it does not address the immediate need to contain an active ransomware event. Rebooting may also interfere with evidence collection or trigger additional malicious actions depending on the malware.