220-1102 exam dumps

220-1102 practice question 205 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 205

Single answerAntivirus

A user reports that their Windows 11 laptop has become noticeably slower and displays repeated antivirus pop-up alerts stating that a Trojan was blocked. The user says the alerts return every time they sign in, even after a quick scan shows no active threats. As the technician, you suspect a malicious file is being recreated at startup. Which action should you take NEXT to best identify and remove the threat?

  1. A

    Run the antivirus solution's full system scan and review quarantine and detection details

  2. B

    Disable real-time protection temporarily and delete random files from the Downloads folder

  3. C

    Uninstall the antivirus software because the repeated alerts indicate it is malfunctioning

  4. D

    Clear the browser cache and cookies, then restart the laptop

Show answer and explanation

Correct answer: A

Explanation

When malware alerts recur at startup, the technician should move beyond a quick scan and use the antivirus product's more comprehensive tools, starting with a full system scan and reviewing quarantine and detection logs. This aligns with common security best practices: verify the threat, identify its location and persistence mechanism, and then remove or quarantine it. In Windows environments, recurring detections at sign-in often indicate persistence through startup folders, Run keys, services, or scheduled tasks. Antivirus vendors such as Microsoft recommend using deeper scans and reviewing protection history or detection details when threats reappear. Disabling protection or uninstalling the antivirus increases risk and does not address root cause.

  • A. Correct.

    Correct. A full system scan is the appropriate next step when a quick scan does not resolve recurring malware alerts. Full scans check more locations, including startup areas, scheduled tasks, temporary folders, and user profile paths where persistence mechanisms may exist. Reviewing quarantine and detection details also helps identify the exact file path, malware name, and whether the antivirus has already isolated part of the infection.

  • B. Incorrect.

    Incorrect. Disabling real-time protection reduces security and can allow the malware to execute or spread. Deleting random files from Downloads is not a reliable remediation method because the malicious file may be located elsewhere or recreated by a startup item, scheduled task, or another malicious process. This reflects a common mistake of taking action before properly identifying the threat.

  • C. Incorrect.

    Incorrect. Repeated alerts usually mean the antivirus is successfully detecting ongoing malicious activity, not that it is broken. Removing the antivirus would leave the system less protected and make cleanup harder. A technician should use the antivirus tools more thoroughly before considering any product issue.

  • D. Incorrect.

    Incorrect. Clearing browser cache and cookies can help with some browser-related issues, but it does not address a Trojan that is triggering antivirus detections at sign-in. Because the problem appears tied to startup persistence, browser cleanup alone is unlikely to identify or remove the source.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam