220-1102 exam dumps

220-1102 practice question 405 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 405

Single answerTrojan

A user reports that after installing a free "video codec" from an unfamiliar website, their Windows 11 laptop began showing fake antivirus pop-ups and making outbound network connections even when no browser is open. The technician suspects a Trojan. What should the technician do FIRST to limit the impact while beginning remediation?

  1. A

    Disconnect the laptop from the network and then begin malware remediation steps

  2. B

    Delete the user's browser history and cached files to stop the pop-ups

  3. C

    Disable User Account Control (UAC) so security tools can remove the infection more easily

  4. D

    Run Disk Cleanup to remove temporary files before taking any other action

Show answer and explanation

Correct answer: A

Explanation

This question tests practical malware response. In CompTIA A+ Core 2 objectives, Trojans are malicious programs disguised as legitimate software and commonly arrive through social engineering, fake installers, or bundled downloads. In a real support scenario, the technician should first contain the threat by disconnecting the device from wired, wireless, VPN, or other network access. That limits command-and-control communication, additional payload downloads, data theft, and spread to other systems. After isolation, standard best practices include identifying and updating antimalware tools as feasible, scanning and removing/quarantining malicious files, scheduling scans if needed, rebooting into safe mode when appropriate, and educating the user to avoid untrusted downloads. This aligns with common incident response guidance from Microsoft security documentation and general malware-remediation best practices: contain first, then eradicate and recover.

  • A. Correct.

    Correct. A Trojan often opens backdoors, downloads additional malware, or communicates with command-and-control systems. The first priority is containment: isolate the infected system from the network to reduce data exfiltration, lateral movement, and further downloads. After isolation, the technician can proceed with standard malware-removal steps such as updating antimalware tools if possible, scanning, quarantining, and validating system integrity.

  • B. Incorrect.

    Incorrect. Clearing browser data may remove some nuisance artifacts, but it does not address the underlying Trojan infection. The scenario includes suspicious outbound connections when the browser is closed, which indicates malware activity beyond normal browser behavior.

  • C. Incorrect.

    Incorrect. Disabling UAC reduces system security and can make the situation worse by allowing malware or tools to run with fewer prompts. Best practice is to keep security controls enabled and use proper administrative procedures during remediation.

  • D. Incorrect.

    Incorrect. Temporary-file cleanup can be useful later in a malware-removal process, but it is not the first action when a Trojan is actively communicating externally. Containment takes priority over general system maintenance.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam