220-1102 exam dumps

220-1102 practice question 422 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 422

Select 2Anti-malware

A user reports that their Windows 11 laptop is displaying frequent pop-up warnings claiming the device is infected and urging them to buy a cleanup tool. The browser homepage has changed, and the system is noticeably slower. You suspect scareware or other malware. Before the device is returned to the user, which TWO actions are the BEST choices to properly remediate the issue using anti-malware best practices?

  1. A

    Boot the system into Safe Mode, run updated anti-malware scans, and remove or quarantine detected threats

  2. B

    Disable User Account Control (UAC) so the anti-malware tool can clean all files without prompts

  3. C

    Update the anti-malware signatures and perform a full system scan after isolating the device from the network

  4. D

    Clear the browser cache and browsing history only, then return the laptop to the user

  5. E

    Uninstall the existing anti-malware product immediately and reinstall it after the user resumes normal work

Show answer and explanation

Correct answers: A, C

Explanation

The best answers are to isolate the system, update anti-malware definitions, run thorough scans, and use Safe Mode when malware may interfere with normal operation. These steps reflect widely accepted malware-removal procedures taught in A+ Core 2: identify symptoms, quarantine/isolate the device, disable unnecessary startup behavior if needed, remediate with updated anti-malware tools, and verify full system functionality afterward. Microsoft security guidance and general endpoint protection best practices support keeping protections enabled, updating intelligence/signatures before scanning, and avoiding security-reducing actions such as disabling UAC. Browser cleanup alone is insufficient when multiple indicators point to active malware.

  • A. Correct.

    Correct. Booting into Safe Mode is a standard malware-removal technique because it can prevent many nonessential startup items and malicious processes from loading, making detection and removal easier. Running updated anti-malware tools and quarantining or removing detected items aligns with common remediation steps for an infected Windows system.

  • B. Incorrect.

    Incorrect. Disabling UAC is not an anti-malware best practice and reduces system security. Anti-malware tools are designed to request elevation when needed. Turning off UAC can make the system more vulnerable and is not a recommended step in malware remediation.

  • C. Correct.

    Correct. Isolating the device from the network helps prevent spread, command-and-control communication, or additional payload downloads. Updating signatures before a full scan improves detection accuracy. A full system scan is appropriate when symptoms suggest a broader compromise, such as scareware, browser hijacking, and performance degradation.

  • D. Incorrect.

    Incorrect. Clearing browser data may remove some unwanted settings or temporary files, but it does not adequately address an active malware infection. Given the fake infection alerts and system slowdown, anti-malware scanning and remediation are required before the system can be considered safe.

  • E. Incorrect.

    Incorrect. Removing the existing anti-malware product is not an appropriate first response and can leave the system less protected during remediation. Standard practice is to update the current tool, scan, quarantine/remove threats, and verify the system is clean. Reinstallation of the security product might be considered later only if the product itself is damaged.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam