220-1102 exam dumps

220-1102 practice question 407 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 407

Single answerVirus

A user reports that their Windows 11 laptop has become unusually slow and keeps opening unwanted browser tabs. Shortly after startup, the antivirus icon disappears from the system tray, and Task Manager closes whenever the user tries to open it. You suspect a virus is actively interfering with security tools. What should the technician do FIRST to best contain the issue and begin remediation?

  1. A

    Disconnect the laptop from the network and boot into Safe Mode to run updated anti-malware scans

  2. B

    Open the default web browser and install multiple free cleanup tools from search results

  3. C

    Run Disk Cleanup to remove temporary files and then restart the computer normally

  4. D

    Disable User Account Control so security tools can run without prompts

Show answer and explanation

Correct answer: A

Explanation

The best first action is containment followed by controlled remediation. In a real support scenario, the signs described, disabled antivirus, blocked Task Manager, browser hijacking, and severe slowdown, indicate possible active malware or a virus interfering with normal tools. CompTIA A+ Core 2 malware-removal methodology emphasizes identifying symptoms, quarantining infected systems, and then using safe remediation steps such as Safe Mode and trusted anti-malware utilities. Microsoft security guidance and industry best practices also support isolating infected endpoints from the network to reduce command-and-control communication, lateral movement, or data loss. After containment, the technician should run updated scans, remove detected threats, verify system stability, re-enable protections if they were disabled, apply updates, and educate the user on safe browsing and download practices.

  • A. Correct.

    Correct. A system showing signs of an active virus that disables security tools should first be contained to prevent further spread or data exfiltration. Disconnecting from the network is a standard first step. Booting into Safe Mode can prevent many malicious processes from loading, making it easier to update and run trusted anti-malware tools. This aligns with common malware-removal best practices taught in A+ Core 2: identify symptoms, quarantine infected systems, disable System Restore if appropriate, remediate, schedule scans and updates, and educate the user.

  • B. Incorrect.

    Incorrect. Downloading random cleanup tools from search results is risky and can worsen the infection, especially on a system already showing signs of malware. Attackers often use fake antivirus or trojanized utilities. Technicians should use trusted, approved security tools from known vendors, ideally after isolating the machine.

  • C. Incorrect.

    Incorrect. Disk Cleanup may remove temporary files, but it is not a malware-removal tool and does not address an active virus that is disabling antivirus and Task Manager. Restarting normally may allow the malicious processes to reload and continue interfering with remediation.

  • D. Incorrect.

    Incorrect. Disabling User Account Control reduces security and does not solve the root problem. UAC helps limit unauthorized changes. Turning it off can make the situation worse by removing a layer of protection that helps block malware from making system-level changes.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam