220-1102 exam dumps

220-1102 practice question 404 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 404

Single answerMalware

A user reports that their Windows 11 laptop suddenly displays frequent pop-up warnings claiming the system is infected and urging them to buy a cleanup tool. The browser homepage has changed, security settings are disabled, and Task Manager closes immediately after opening. The device is still connected to the company network. As the technician responding to this incident, what should you do FIRST?

  1. A

    Run System Restore to roll the laptop back to a previous restore point

  2. B

    Disconnect the laptop from the network to contain the infection

  3. C

    Install and run a different web browser to bypass the pop-ups

  4. D

    Uninstall the suspicious cleanup tool from Programs and Features

Show answer and explanation

Correct answer: B

Explanation

The best first action is to disconnect the infected system from the network. In A+ Core 2 malware scenarios, CompTIA commonly expects candidates to follow a practical malware-removal process: identify malware symptoms, quarantine or isolate the infected device, disable System Restore if appropriate, remediate the infection with updated tools, schedule scans, re-enable protections, and educate the user. Isolation comes first because it limits spread and reduces further damage. The described symptoms are consistent with rogue antivirus/scareware and possibly broader malware infection because they include fake infection alerts, changed browser settings, and disabled administrative tools. Standard security best practices from Microsoft and incident response guidance also prioritize containment before eradication.

  • A. Incorrect.

    System Restore may be useful later in remediation, but it is not the first step. CompTIA malware-removal best practices emphasize identifying symptoms and quarantining or isolating the affected system before attempting changes. Restoring too early could fail, spread the infection further if the machine remains connected, or leave active malware in place.

  • B. Correct.

    This is correct. When malware is actively affecting system behavior and the device remains connected to the company network, the first priority is containment. Disconnecting the system from the network helps prevent lateral movement, data exfiltration, command-and-control communication, or infection of shared resources. This aligns with standard incident response and CompTIA's malware-removal methodology to identify and isolate the infected system before remediation.

  • C. Incorrect.

    Changing browsers does not address the underlying malware. The pop-ups, homepage changes, and disabled tools indicate system-level compromise, not just a browser issue. A technician might pick this if they assume the problem is limited to adware in one browser, but the broader symptoms show the infection is affecting the operating system.

  • D. Incorrect.

    Removing a suspicious program can be part of cleanup, but it is not the first action while the system is still connected to the network and actively compromised. Also, some malware does not appear cleanly in Programs and Features, and attempting removal before isolating the device may trigger additional malicious activity or fail because the malware is still running.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam