HOTSPOT
You are security administrator investigating a potential infection on a network.
Click on each host and firewall. Review all logs to determine which host originated the Infecton and
then deny each remaining hosts clean or infected.

Looks right to me, seen similar drag-and-drop hotspot setups in the official practice tests. If a host's logs show they quarantined svch0st.exe successfully, CompTIA expects you to call it clean. Origin is 192.168.10.22, with 192.168.10.41 and 10.10.9.18 counted as infected. Let me know if you see a different interpretation, but pretty sure that's what the exam wants.
Origin: 192.168.10.22
Infected: 192.168.10.41 & 10.10.9.18
Clean: 192.168.10.37 & 10.10.9.12
CompTIA usually treats hosts as clean if they detected and fully quarantined the malware, even if it showed up in logs, so I think this matches what they want here-unless anyone interprets their criteria differently.
Looks solid to me-origin is definitely 192.168.10.22, since that's where the first signs of disabled security tools pop up. For CompTIA, if a host's logs show svch0st.exe was quarantined successfully (like 192.168.10.37 and 10.10.9.12), they're labeled clean even though something happened there. Infected is for the hosts where that didn't work (192.168.10.41, 10.10.9.18). Pretty sure that's what the exam expects but I'm open if someone spots a different logic here.
Yeah, that's how I'd split it up too. Origin is 192.168.10.22 because it's the first to get the malicious svch0st.exe running and disables security tools, then spreads out. If the logs say a host fully quarantined it (like 192.168.10.37 and 10.10.9.12), that's "clean" even though malware showed up there for a sec. Pretty sure that's CompTIA logic, but open to pushback if someone interprets the logs differently.
Yeah, I’m with the majority here. If the logs show successful quarantine of svch0st.exe like on 10.10.9.12 and 192.168.10.37, CompTIA usually marks those hosts as clean since remediation worked. Origin is 192.168.10.22 for sure, infected are the ones where it couldn’t be quarantined (192.168.10.41 and 10.10.9.18). Pretty sure this matches what they expect, but always double-check log details just in case!
Origin is 192.168.10.22, infected are 192.168.10.41 and 10.10.9.18, clean are 192.168.10.37 and 10.10.9.12.
Some folks mix up 10.10.9.12 but it shows it quarantined svch0st.exe successfully, so pretty sure it counts as clean here by exam logic. If quarantine didn’t count, 10.10.9.12 might look infected at first glance.
