220-1102 Question 627
Single answerAltered system or personal filesA user reports that several Word documents in their Documents folder now have unfamiliar filenames and cannot be opened. In the same folder, there is a text file demanding payment in cryptocurrency to restore access. The user says the issue started after opening an email attachment from an unknown sender. After isolating the PC from the network, which action should the technician take NEXT to best address the altered personal files while following malware-remediation best practices?
- A
Pay the ransom immediately so the files can be decrypted before more damage occurs
- B
Run anti-malware scans, remove the infection, and then restore the affected files from a known-good backup
- C
Rename the affected files back to their original names and reboot the computer
- D
Use Disk Cleanup to remove temporary files and then retry opening the documents
Show answer and explanation
Correct answer: B
Explanation
This scenario describes ransomware: personal files have been altered or encrypted, filenames have changed, and a ransom note is present after a suspicious email attachment was opened. In A+ Core 2 malware-remediation methodology, the technician should first identify and isolate the infected system, then use updated anti-malware tools to remove the threat, schedule scans as needed, and remediate persistence. After the infection is removed, the proper recovery method is to restore affected files from a known-good backup or other trusted recovery source. Paying the attacker is not considered a best practice because it does not ensure decryption and leaves the organization exposed. Microsoft and other security guidance consistently emphasize maintaining offline or otherwise protected backups and restoring from them after eradication of the malware.
- A. Incorrect.
Incorrect. Paying a ransom is not a recommended remediation step. It does not guarantee file recovery, may encourage further criminal activity, and does not remove the underlying malware. Security best practices prioritize containment, eradication, and recovery from trusted backups whenever possible.
- B. Correct.
Correct. The scenario strongly indicates ransomware, which commonly alters or encrypts personal files and leaves a ransom note. After isolating the system, the next appropriate step is to scan and remove the malware, then recover data from a verified clean backup. This aligns with standard incident-response and malware-removal practices: quarantine the system, remediate the infection, and restore affected files from known-good sources.
- C. Incorrect.
Incorrect. Ransomware-altered or encrypted files are not fixed by simply changing filenames. The underlying file contents have been modified or encrypted, so renaming does not restore usability. Rebooting may also allow malware persistence mechanisms to continue operating.
- D. Incorrect.
Incorrect. Disk Cleanup removes temporary and unnecessary system files, but it does not decrypt or repair ransomware-encrypted documents. Someone might choose this option if they confuse file corruption caused by low disk space or temp-file issues with malicious alteration of user data.