220-1102 Question 415
Single answerAdwareA user reports that after installing a free PDF utility, their Windows 11 laptop now displays frequent pop-up advertisements even when the browser is closed. The default search engine has changed, new browser toolbars appeared, and web pages sometimes redirect to shopping sites. You suspect adware. Which action should the technician take FIRST to begin remediation while following A+ malware-removal best practices?
- A
Run anti-malware scans after identifying and quarantining suspicious programs and browser extensions
- B
Reimage the laptop immediately to guarantee that all advertisements are removed
- C
Replace the SSD because adware commonly embeds itself in storage hardware firmware
- D
Disable User Account Control so the technician can remove hidden advertising components more easily
Show answer and explanation
Correct answer: A
Explanation
This scenario matches common adware behavior: bundled installation with freeware, pop-up ads, browser redirects, changed search settings, and unwanted toolbars. In A+ Core 2, technicians are expected to recognize adware symptoms and apply standard malware-removal best practices rather than immediately taking destructive or unsafe actions. Practical remediation includes uninstalling suspicious recently installed applications, removing malicious or unwanted browser extensions, resetting browser settings if needed, updating and running anti-malware tools, and confirming that the symptoms no longer occur. CompTIA objectives commonly emphasize a structured malware-removal process, and Microsoft security guidance also supports using trusted security software, removing unwanted apps and extensions, and restoring browser settings when adware or potentially unwanted applications are present.
- A. Correct.
Correct. Adware commonly arrives bundled with freeware and often installs unwanted applications, browser extensions, search hijackers, and toolbars. CompTIA A+ malware-removal methodology begins with identifying malware symptoms, quarantining infected systems if needed, disabling System Restore when appropriate, remediating the infection, scheduling scans and updates, and then re-enabling protections and educating the user. Running reputable anti-malware tools and removing suspicious bundled software and extensions is the appropriate first remediation step in this scenario.
- B. Incorrect.
Incorrect. Reimaging is sometimes necessary for severe or persistent infections, but it is not the first step for a typical adware case. Adware is often removable through standard malware-removal procedures, uninstalling suspicious software, removing browser add-ons, and scanning with updated security tools. Jumping straight to reimaging skips normal troubleshooting and remediation.
- C. Incorrect.
Incorrect. Adware does not commonly infect SSD firmware. This option confuses adware with highly advanced firmware-level threats, which are rare and not the expected cause of browser pop-ups, redirects, and unwanted toolbars after installing freeware. Replacing hardware would be unnecessary and costly.
- D. Incorrect.
Incorrect. Disabling User Account Control reduces system security and is not a recommended malware-removal practice. A technician should use administrative tools properly, not weaken protections to make removal easier. Lowering security settings can allow additional unwanted changes or malware activity.