220-1102 exam dumps

220-1102 practice question 464 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 464

Select 34. Remediate infected systems

A user reports that their Windows 11 laptop suddenly displays repeated browser pop-ups, runs unusually slowly, and is attempting to send large amounts of outbound network traffic even when no applications are open. You suspect malware infection. The user needs the system cleaned, but you also want to follow proper remediation procedure and reduce the chance of reinfection or data loss. Which THREE actions should you take first?

  1. A

    Disconnect the laptop from the network and disable Wi-Fi/Bluetooth connections

  2. B

    Document the symptoms, quarantine the affected system, and ask the user about recent downloads or email attachments

  3. C

    Immediately reformat the drive before attempting any malware scans

  4. D

    Run updated anti-malware scans, preferably from Safe Mode or a trusted recovery environment if needed

  5. E

    Reconnect the system to verify whether the outbound traffic returns before making changes

  6. F

    Delete random suspicious files manually from C:\Windows to speed up cleanup

Show answer and explanation

Correct answers: A, B, D

Explanation

The best initial response to a suspected malware infection is to contain the system, document and investigate the symptoms, and then use trusted, updated anti-malware tools to remediate. This aligns with standard CompTIA A+ Core 2 malware-removal methodology: identify malware symptoms, quarantine infected systems, disable system restore if required by procedure, remediate using updated tools, schedule scans and updates, re-enable protections, educate the user, and confirm full functionality afterward. Microsoft security guidance and general incident-response best practices also emphasize isolation first to prevent spread or data exfiltration, followed by evidence-aware investigation and controlled remediation. Reformatting may become necessary later if the infection cannot be reliably removed, but it is not typically the first action when beginning remediation.

  • A. Correct.

    Correct. A key first step in remediating an infected system is to contain the threat. Disconnecting the device from wired and wireless networks helps prevent data exfiltration, command-and-control communication, lateral movement, and further spread to other systems. Disabling Wi-Fi and Bluetooth is appropriate because malware can use active interfaces to communicate or propagate.

  • B. Correct.

    Correct. CompTIA A+ remediation best practice includes identifying and researching symptoms, quarantining infected systems, and documenting findings. Asking the user about recent downloads, links, removable media, or email attachments helps identify the infection source and supports later user education and prevention. Documentation also supports incident tracking and repeatable remediation.

  • C. Incorrect.

    Incorrect. Reformatting can remove malware, but it is not one of the first actions in a standard remediation workflow unless directed by policy or when cleanup is not feasible. Best practice is to contain the system, assess the issue, attempt remediation with trusted tools, and then restore or rebuild only if necessary. Immediately formatting may also destroy evidence and complicate recovery of needed data.

  • D. Correct.

    Correct. After isolation and initial assessment, running updated anti-malware tools is an appropriate remediation step. Safe Mode or a trusted recovery environment can reduce interference from active malware processes and improve removal success. Using current definitions is important because outdated tools may miss current threats.

  • E. Incorrect.

    Incorrect. Reconnecting the system to observe malicious traffic is unsafe and contrary to containment best practices. If malware is already suspected, reconnecting can allow continued exfiltration, reinfection, or spread. Monitoring should be done in a controlled environment, not by putting the infected endpoint back on the production network.

  • F. Incorrect.

    Incorrect. Manually deleting files from system directories without verified analysis is risky and not a recommended first response. It can damage the operating system, miss persistence mechanisms such as scheduled tasks or registry entries, and fail to remove the actual malware. Proper remediation relies on trusted security tools and a structured process rather than guesswork.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam