220-1102 exam dumps

220-1102 practice question 414 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 414

Single answerFileless

A help desk technician is investigating a Windows 11 workstation that briefly opened a PowerShell window after a user clicked a link in a phishing email. The antivirus scan finds no malicious executable files on disk, but the endpoint detection tool shows PowerShell launching encoded commands and making outbound connections to an unfamiliar IP address. Which type of malware most likely affected the system?

  1. A

    A fileless malware attack using legitimate system tools in memory

  2. B

    A boot sector virus that infected the system drive

  3. C

    A ransomware variant that encrypted local documents

  4. D

    A worm that spread through removable media by copying executable files

Show answer and explanation

Correct answer: A

Explanation

This scenario describes a classic fileless malware pattern: a user initiates the attack by clicking a phishing link, then a legitimate administrative tool such as PowerShell runs malicious code directly in memory. Fileless attacks often evade traditional signature-based antivirus because they may not place a detectable executable on the disk. On CompTIA A+ Core 2, candidates should recognize that suspicious use of built-in scripting and administration tools, especially PowerShell with encoded commands, is a common sign of fileless malware. Best practices for response include isolating the affected host, reviewing PowerShell and security logs, blocking the malicious connection, updating endpoint protections, and retraining the user on phishing awareness. Microsoft security guidance and industry endpoint detection best practices commonly highlight PowerShell abuse, WMI misuse, and in-memory execution as indicators of fileless attacks.

  • A. Correct.

    Correct. Fileless malware commonly uses built-in tools such as PowerShell, WMI, or script engines to execute malicious commands in memory without dropping a traditional executable to disk. The scenario specifically mentions encoded PowerShell commands, no malicious file found by antivirus, and outbound network activity, which strongly matches fileless behavior.

  • B. Incorrect.

    Incorrect. A boot sector virus targets the boot record or startup process of a drive. The scenario does not mention startup failures, boot issues, or signs of compromise in the boot process. Instead, it describes user-triggered PowerShell execution after a phishing link, which is more consistent with fileless malware.

  • C. Incorrect.

    Incorrect. Ransomware usually presents clear symptoms such as encrypted files, ransom notes, or inaccessible documents. In this case, there is no indication that files were encrypted. The key clue is execution through PowerShell with no malicious executable on disk, which points away from ransomware.

  • D. Incorrect.

    Incorrect. A worm that spreads through removable media typically copies itself as files to other drives or devices and propagates without requiring a phishing link. The scenario centers on malicious in-memory execution after a phishing email and does not mention USB devices or copied executable files.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam