220-1102 Exam QuestionsBrowse all questions from this exam

220-1102 Exam - Question 190


A user is unable to access files on a work PC after opening a text document. The text document was labeled “URGENT PLEASE READ.txt - In active folder, .txt file titled urgent please read”. Which of the following should a support technician do FIRST?

Show Answer
Correct Answer: AB

When dealing with a potential malware incident, the first step is to contain the threat and prevent it from spreading to other systems. Therefore, the initial action should be to quarantine the host computer. This isolation will help ensure that any potential malware does not propagate to other networked systems. Once the system is quarantined, further steps, such as running antivirus scans and investigating how the malware was installed, can be taken.

Discussion

11 comments
Sign in to comment
MehsotopesOption: B
Aug 6, 2023

The technician has not confirmed that this is malware. if customer is still there, the technician should definitely inquire if the customer knows where that file came from, & what it is. If the customer is not reachable, technician should first scan the computer for viruses.

Mango7
Oct 10, 2023

I like all your explanations, your reasonings are always on point brother.

FarticusOption: C
May 23, 2023

The answer would be C. 3.2 of the Comptia 1102 exam objectives states the following: Given a scenario, use best practice procedures for malware removal. 1. Investigate and verify malware symptoms 2.Quarantine infected systems 3.Disable System Restore in Windows 4.Remediate infected systems a. Update anti-malware software b.Scanning and removal techniques (e.g., safe mode, preinstallation environment) 5.Schedule scans and run updates 6.Enable System Restore and create a restore point in Windows 7. Educate the end user

Calebdames
May 26, 2023

So B "1. Investigate and verify malware symptoms" how else do you investigate and verify malware symptons,

ShukazoPenguin
Dec 1, 2023

C implies that the malware was already discovered, so it's B.

mr_reyesOption: A
May 8, 2023

Why wouldn't you ALWAYS quarantine the system before doing any other step? To prevent a possible spread.

idoit
May 9, 2023

The answer is phrased strangely. It says quarantine the host, which is normal, but it says "in the antivirus system" which is odd and I am not even sure what it means. You would normally quarantine it from the network.

DadadagreatOption: A
Jul 18, 2023

I would for letter A (Quarantine)

PraygeForPassOption: B
Aug 3, 2023

This is an interesting one. I don't know if I'm thinking too hard, but .txt extensions cannot execute anything. Even if there is code inside of it. So when opening it, all you will see is text. Because of this I would just use B, to check if there's anything malicious on the machine. If I'm not thinking hard and they are expecting a typical step, I would pick A, quarantine.

Rizierr
Dec 13, 2023

this question is phrased so weird. i dont understand what its saying

354fcf1
Jul 12, 2024

I can't read this either lol

Pisces225Option: C
Dec 15, 2023

The questions says the filename is “URGENT PLEASE READ.txt - In active folder, .txt file titled urgent please read”. Just because there's a .txt extension in the middle of the file name doesn't make this a text file. If Windows Explorer settings are default then known file extension types, such as .exe, will not be displayed. The technician should start at step one by investigating and verifying symptoms before proceeding to quarantine if confirmed.

dcv1337Option: B
Jul 18, 2023

I believe it's B but A is the next best answer in my opinion.

b0bbyOption: C
Mar 14, 2024

Order of operations C then B then A. Questions is where are you. My perspective we know that malware on the PC but not how it got on my answer is C. In real world I'd be Quarantining the machine right away even as I continuing investigating on how it was installed to protect my other machines and keeping it from spreading. This as what seems to be the consistency another bad poorly worded question.

b0bby
Mar 14, 2024

Sorry Order of operations is C then A then B.

UranusNeptuneOption: B
May 21, 2024

The answer is B because on the practice test I chose C which it told me was incorrect. Instead it told me the answer is B. So the Answer to this question is B

Phillyboy20_Option: B
May 25, 2024

The question doesn't mention that it is malware, so it should be assumed that it is malware.