exam questions

Exam 220-1102 All Questions

View all questions & answers for the 220-1102 exam

Exam 220-1102 topic 1 question 123 discussion

Actual exam question from CompTIA's 220-1102
Question #: 123
Topic #: 1
[All 220-1102 Questions]

A technician received a call stating that all files in a user's documents folder appear to be changed, and each of the files now has a .lock file extension. Which of the following actions is the FIRST step the technician should take?

  • A. Run a live disk clone.
  • B. Run a full antivirus scan.
  • C. Use a batch file to rename the files.
  • D. Disconnect the machine from the network.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Dido1963
Highly Voted 10 months, 3 weeks ago
A ransomware attack may be the reason for the lock-files. And the second step of malware removal steps is, to bring the computer into Quarantine. (First step was "Identify and research malware symptoms", and to see *.lock-Files is that step)
upvoted 10 times
...
NotAHackerJustYet
Highly Voted 9 months, 2 weeks ago
The first step the technician should take is to disconnect the machine from the network. This is important to prevent the spread of the malicious software or virus which has caused the files to be changed, and to prevent the user from opening any additional files which may be affected. Disconnecting the machine from the network will also prevent the hacker from continuing their attack. The other options are not appropriate as a first step, as they will not prevent further attacks or the spread of the malicious software.
upvoted 5 times
...
JollyGinger27
Most Recent 9 months ago
Selected Answer: D
The first step is to identify the symptoms of malware, which was done already by looking at the .lock files, likely caused by ransomware. The first thing to do after that is to quarantine (disconnect) the machine from the network to prevent further contamination to other systems. D is the answer
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago