220-1102 exam dumps

220-1102 practice question 733 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 733

Single answerIncident response

A help desk technician receives a call from a user who reports that a company laptop suddenly began displaying repeated antivirus pop-ups, the desktop background changed without permission, and the system is now sending large amounts of network traffic according to the monitoring dashboard. The user is currently connected to the corporate network and still logged in. According to incident response best practices, what should the technician do FIRST?

  1. A

    Disconnect the laptop from the network to contain the potential malware infection

  2. B

    Run a full antivirus scan immediately to remove the malicious files

  3. C

    Reimage the laptop as quickly as possible to restore the user's productivity

  4. D

    Ask the user to continue working while the security team reviews the alerts remotely

Show answer and explanation

Correct answer: A

Explanation

This question focuses on the practical application of incident response in an end-user support environment. For CompTIA A+ Core 2, candidates should know the basic incident response process: identify, contain, eradicate, recover, and document. In this scenario, the symptoms strongly suggest an active malware infection or compromise. Because the device is still connected to the corporate network and generating abnormal traffic, the technician's first action should be containment by isolating the laptop from the network. After containment, the issue should be documented and escalated according to organizational policy, followed by malware removal, validation, and recovery steps. This sequence is consistent with common security best practices such as those described in NIST incident handling guidance, which emphasizes containment before eradication and recovery.

  • A. Correct.

    Correct. In standard incident response, the first priority after identifying a likely security incident is containment. Disconnecting the device from the network helps prevent further spread, data exfiltration, command-and-control communication, or additional damage. On the A+ Core 2 exam, this aligns with the incident response sequence of identifying the issue and then containing it before eradication and recovery activities.

  • B. Incorrect.

    Incorrect. Running antivirus may be part of eradication, but it is not the first action when the system is actively suspected of being compromised and connected to the network. If the machine remains online during scanning, malware could continue spreading or communicating externally. A common mistake is jumping straight to removal before containing the incident.

  • C. Incorrect.

    Incorrect. Reimaging may eventually be appropriate during recovery, but doing so immediately skips key response steps such as containment, documentation, and preserving the situation for escalation or further investigation. This option reflects the misconception that restoring service is always the top priority, even before limiting the scope of an active incident.

  • D. Incorrect.

    Incorrect. Allowing the user to keep using the device increases the risk of spreading malware, corrupting evidence, or worsening the compromise. Although remote review may occur later, keeping the infected system active on the corporate network is not consistent with basic containment best practices.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam