220-1102 exam dumps

220-1102 practice question 356 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 356

Single answerDefender Antivirus

A small office uses Windows 10 laptops with Microsoft Defender Antivirus enabled. A user reports that every time they download a vendor's hardware diagnostic tool from the vendor's official website, Defender immediately quarantines the file as a threat. You verify the URL is correct, other users need the same tool, and the business wants to keep Defender protection enabled. What is the BEST action to allow use of this specific tool while minimizing security risk?

  1. A

    Turn off real-time protection in Microsoft Defender Antivirus before downloading the file, then turn it back on afterward

  2. B

    Create a Defender exclusion for the specific file or trusted folder after verifying the file is legitimate

  3. C

    Disable Microsoft Defender Antivirus entirely and install a different antivirus product

  4. D

    Restore the quarantined file and instruct users to ignore future Defender alerts for this application

Show answer and explanation

Correct answer: B

Explanation

The best answer is to create a targeted Microsoft Defender Antivirus exclusion only after confirming the file is genuine and obtained from a trusted source. In a real support scenario, the technician should avoid broad actions such as disabling real-time protection or removing antivirus protection entirely. Microsoft documents exclusion options for files, folders, file types, and processes, but best practice is to use the narrowest exclusion necessary because exclusions reduce scanning for those items. This aligns with A+ Core 2 objectives emphasizing practical malware protection, safe remediation, and maintaining endpoint security while supporting legitimate business applications.

  • A. Incorrect.

    This is incorrect because disabling real-time protection reduces security for the entire system during that period and is broader than necessary. Although an administrator might be tempted to do this for a quick workaround, it exposes the device to other threats and is not the best practice when the goal is to allow only one known-good tool.

  • B. Correct.

    This is correct because creating a narrowly scoped exclusion for a verified legitimate tool allows the organization to keep Microsoft Defender Antivirus enabled while minimizing the impact on overall protection. The key is to verify the file's source and legitimacy first, then use the smallest exclusion scope possible, such as a specific file or folder, rather than disabling protection globally.

  • C. Incorrect.

    This is incorrect because replacing Defender is unnecessary if the issue involves one legitimate application being flagged. CompTIA A+ expects candidates to choose the least disruptive and most secure solution. Disabling built-in protection and deploying another product creates more administrative overhead and does not address the immediate false-positive situation appropriately.

  • D. Incorrect.

    This is incorrect because simply restoring a quarantined file without creating a controlled exception may result in Defender quarantining it again. Telling users to ignore security alerts is also poor security practice and can train them to dismiss legitimate warnings in the future.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam