N10-009 exam dumps

N10-009 practice question 272 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 272

Single answerMalware

A network administrator notices that several workstations are generating a high volume of outbound connections to random external IP addresses over TCP 25 and TCP 445. Users also report that files on a shared drive are being renamed and becoming inaccessible. The organization needs to contain the issue quickly while preserving evidence for later analysis. Which action should the administrator take FIRST?

  1. A

    Disconnect the affected systems from the network or place them in a quarantine VLAN

  2. B

    Reboot the affected systems to stop the suspicious processes

  3. C

    Delete the renamed files from the shared drive to prevent further spread

  4. D

    Apply operating system patches to the affected workstations immediately

Show answer and explanation

Correct answer: A

Explanation

The best first response to suspected malware with worm-like or ransomware-related behavior is containment. In this scenario, the combination of unusual outbound traffic, possible SMTP abuse on TCP 25, SMB-related activity on TCP 445, and inaccessible renamed files indicates active compromise affecting both network behavior and file availability. Standard incident response practice prioritizes identification and containment before eradication and recovery. Network isolation, such as disconnecting systems or moving them to a quarantine VLAN, limits further propagation and preserves evidence for analysis. This aligns with common incident handling guidance from NIST SP 800-61 Computer Security Incident Handling Guide, which emphasizes containment strategies early in the response process. After containment, the organization should collect evidence, identify the malware type and infection vector, eradicate the threat, patch vulnerable systems, restore from known-good backups if needed, and monitor for reinfection.

  • A. Correct.

    Correct. Isolating infected hosts is the best first step to contain malware activity while preserving the systems for investigation. The symptoms suggest self-propagating malware or ransomware/worm behavior, with mass outbound connections and file impact on shared storage. Removing the systems from normal network access, either physically or through a quarantine VLAN, helps stop lateral movement and additional command-and-control or spam activity without immediately destroying volatile evidence.

  • B. Incorrect.

    Incorrect. Rebooting may interrupt some malware, but it can also destroy volatile forensic evidence such as running processes, active network connections, memory-resident payloads, and logged-in sessions. It also does not address continued spread if the systems reconnect to the network afterward. This is a common mistake when administrators try to quickly 'fix' symptoms before containment.

  • C. Incorrect.

    Incorrect. Deleting the renamed files does not contain the infected endpoints and may destroy evidence related to the scope and timing of the incident. If the files were encrypted or modified by malware, deletion could also worsen business impact by removing data that might be recoverable from backups or through incident response procedures.

  • D. Incorrect.

    Incorrect. Patching is an important remediation step after containment, especially if the malware exploited a known vulnerability, but applying patches immediately is not the first action during an active outbreak. The priority is to stop the spread and preserve evidence. Patching while hosts remain active on the network may not prevent ongoing malicious activity already in progress.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam