220-1102 Question 457
Single answerUnprotected systems (missing antivirus/missing firewall)A small accounting office reports that one Windows 11 workstation has been running unusually slowly and displaying frequent pop-up ads in the browser. During your initial assessment, you discover that Microsoft Defender Antivirus real-time protection is turned off, no third-party antivirus is installed, and the Windows Defender Firewall is disabled for the active network profile. The user needs to stay connected to the company network to access a shared accounting application. Which action should you take FIRST to reduce risk while beginning remediation?
- A
Reconnect the workstation to the network share and begin uninstalling suspicious browser extensions before changing any security settings
- B
Enable the host firewall and antivirus protection immediately, then update signatures and run a full malware scan
- C
Leave the system as-is until after business hours so the user can continue working without interruption
- D
Reset the browser to default settings and clear temporary files, because the pop-up ads are most likely caused only by adware in the browser
Show answer and explanation
Correct answer: B
Explanation
The best first action is to restore baseline protections on the endpoint by enabling antivirus and the host firewall, then updating definitions and performing a full scan. In a real support scenario, an unprotected workstation on a company network presents immediate risk. CompTIA A+ Core 2 emphasizes identifying and addressing malware symptoms, applying malware-removal best practices, and recognizing the importance of endpoint security controls such as anti-malware software and host firewalls. Microsoft security guidance for Windows also supports using Microsoft Defender Antivirus and Microsoft Defender Firewall as core protections on Windows systems. While additional steps such as disconnecting from the network, removing malicious extensions, and checking for persistence mechanisms may be appropriate depending on company policy and the severity of compromise, the question asks for the FIRST action to reduce risk while beginning remediation on a system missing both antivirus and firewall protection.
- A. Incorrect.
This is incorrect because the system is currently unprotected. Reconnecting it to normal network activity and focusing first on browser cleanup leaves the workstation exposed to additional threats and possible lateral movement. Suspicious extensions may be part of the issue, but restoring basic protections should come first.
- B. Correct.
This is correct because the machine is missing two core endpoint protections: antivirus and a host-based firewall. Re-enabling antivirus protection and the local firewall is the most appropriate first step to reduce immediate exposure. Updating signatures and running a full scan follows standard malware-remediation best practice and helps identify active threats while the system remains usable for controlled remediation.
- C. Incorrect.
This is incorrect because delaying action on an unprotected system increases risk to both the endpoint and the rest of the organization. A workstation on a business network without antivirus and with the firewall disabled is more vulnerable to malware infection, command-and-control traffic, and unauthorized inbound or outbound communication.
- D. Incorrect.
This is incorrect because browser resets and temporary file cleanup may help remove symptoms, but they do not address the larger security issue: the workstation lacks endpoint protection. The misconception is assuming the browser is the only problem when the disabled antivirus and firewall indicate the system may already be compromised or more easily exploited.