220-1102 Question 119
Single answerInformationalA help desk technician receives multiple reports that users are seeing pop-up messages claiming, "Your computer is infected," along with links to call a support number. The antivirus scan shows no active malware, and the browser homepage has not changed. The technician determines the messages are informational security alerts generated by a malicious website, not by the operating system or antivirus product. Which action should the technician take FIRST to address the issue while following A+ Core 2 best practices?
- A
Instruct users to call the number in the alert to verify whether the warning is legitimate
- B
Close the browser tab or process, clear browser cache/site data if needed, and educate users not to interact with the message
- C
Reimage every affected computer immediately because any security pop-up confirms a full system compromise
- D
Disable the antivirus notifications permanently so users will not confuse legitimate alerts with fake ones
Show answer and explanation
Correct answer: B
Explanation
This question focuses on handling an informational security event in a real support scenario. In A+ Core 2, technicians are expected to distinguish between actual infection indicators and social engineering or scareware tactics. A fake browser alert that urges the user to call a number is commonly associated with tech support scams. The appropriate first response is to stop user interaction with the page, close the browser tab or process if it is difficult to dismiss, clear browser data or permissions when needed, and educate the user not to click similar messages in the future. This aligns with standard security awareness guidance from organizations such as CISA and Microsoft, which recommend avoiding interaction with suspicious pop-ups, not calling unsolicited support numbers, and removing browser artifacts if the issue persists. Reimaging and disabling security tools are not appropriate first actions when there is no evidence of an actual compromise.
- A. Incorrect.
This is incorrect. Calling the number in a fake security alert is a common social engineering trap used in tech support scams. The purpose of the message is often to scare the user into contacting an attacker. Best practice is to avoid interacting with suspicious pop-ups, links, or phone numbers presented by untrusted websites.
- B. Correct.
This is correct. Informational security incidents such as browser-based scareware or fake alerts are often handled first by stopping the immediate interaction, closing the tab or browser process if necessary, and removing cached content or site permissions that may continue the behavior. User education is also critical so the same scam is not triggered again. This response is practical, minimally disruptive, and appropriate when no signs of actual malware infection are present.
- C. Incorrect.
This is incorrect. A fake browser pop-up does not by itself prove the endpoint is fully compromised. Reimaging may be appropriate in severe cases, but it is not the first step when the issue is isolated to a malicious or deceptive web page and no evidence of infection has been found. Choosing this option reflects the misconception that every alarming message indicates a confirmed malware event.
- D. Incorrect.
This is incorrect. Disabling antivirus notifications reduces visibility into legitimate security events and weakens endpoint protection. The problem in this scenario is a malicious website generating deceptive content, not the antivirus product itself. Suppressing real alerts would create additional security risk rather than solve the root cause.