220-1102 exam dumps

220-1102 practice question 410 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 410

Single answerKeylogger

A help desk technician is troubleshooting a Windows 11 laptop used by an accounting employee. The user reports that several business websites are prompting for password resets after logins from unfamiliar locations. During the visit, the technician notices the browser occasionally becomes unresponsive when the user types credentials, but antimalware scans have not yet been run. The technician suspects a keylogger. Which action should the technician take FIRST to best contain the issue and follow good security practice?

  1. A

    Disconnect the laptop from the network and begin malware remediation procedures

  2. B

    Ask the user to change all passwords immediately from the affected laptop

  3. C

    Clear the browser cache and cookies to remove any captured credentials

  4. D

    Update the web browser to the latest version before taking any other action

Show answer and explanation

Correct answer: A

Explanation

This question tests practical incident response for a suspected keylogger infection. In A+ Core 2 security scenarios, the best first step is usually containment: isolate the affected endpoint from the network to prevent additional data loss and limit further attacker communication. A keylogger is malware designed to capture user input, especially credentials, so entering passwords on the compromised system should be avoided. After isolation, standard best practice is to run updated antimalware tools, investigate startup items and suspicious processes, remove the malware, verify the system is clean, and then have the user change passwords from a known-good device. This approach is consistent with common security guidance such as incident response lifecycle principles from NIST, particularly containment before eradication and recovery.

  • A. Correct.

    Correct. If a keylogger is suspected, the priority is containment. Disconnecting the system from the network helps stop further exfiltration of captured keystrokes and reduces ongoing risk while remediation begins. This aligns with standard incident response practice: identify, contain, eradicate, and recover. After isolation, the technician can run antimalware tools, investigate persistence mechanisms, and coordinate password changes from a known-clean device.

  • B. Incorrect.

    Incorrect. Changing passwords from the potentially compromised laptop is risky because a keylogger could capture the new credentials as well. Password resets should be performed only after the infected system is isolated and ideally from a different trusted device. This is a common mistake because password changes seem urgent, but doing so from the compromised endpoint can worsen the incident.

  • C. Incorrect.

    Incorrect. Clearing cache and cookies may remove stored session data or temporary files, but it does not address a keylogger, which captures keystrokes at the OS, driver, application, or malicious process level. Someone might choose this because browser-related symptoms are present, but the scenario points to credential theft, not simply a browser storage issue.

  • D. Incorrect.

    Incorrect. Keeping software updated is an important preventive control, but it is not the first response when active malware is suspected. Updating the browser does not contain a currently running keylogger and could allow the device to remain online and continue leaking data. Containment takes precedence over routine patching in this situation.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam