220-1102 exam dumps

220-1102 practice question 466 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 466

Single answer6. Scan and removal techniques (e.g., safe mode, preinstallation environment)

A user's Windows 11 laptop began displaying fake antivirus pop-ups and became extremely slow after opening an email attachment. When you try to sign in normally, the desktop loads briefly and then the system reboots. The company wants the fastest method to remove the malware while minimizing the chance that the malicious process will start during cleanup. Which action should you take FIRST?

  1. A

    Boot the system into Safe Mode and run updated antimalware scans

  2. B

    Run Disk Cleanup to remove temporary files and then restart normally

  3. C

    Use System Restore from within the normal Windows boot to roll back the last restore point

  4. D

    Open Task Manager during normal startup and end suspicious processes before scanning

Show answer and explanation

Correct answer: A

Explanation

The best first action is to boot into Safe Mode and run antimalware scans because the goal is to prevent the malware from loading while performing cleanup. This aligns with standard malware-removal best practices taught for A+ Core 2: identify symptoms, quarantine the system if needed, disable or limit malware execution, remediate using appropriate tools, schedule scans and updates, and verify full functionality afterward. Safe Mode is specifically useful when malware interferes with normal startup or causes instability. If Safe Mode is unsuccessful, an offline scan or recovery environment such as Windows Recovery Environment (WinRE) or bootable media may be the next step. Microsoft documentation describes Safe Mode as loading only essential drivers and services, which is why it is commonly used during troubleshooting and malware remediation.

  • A. Correct.

    Correct. Safe Mode starts Windows with a minimal set of drivers and services, which helps prevent many malicious startup items and processes from loading. This makes it a standard first step for malware remediation when normal boot is unstable or malware interferes with cleanup. After booting into Safe Mode, the technician should update the antimalware tool if possible and run a full scan.

  • B. Incorrect.

    Incorrect. Disk Cleanup can remove temporary files and free space, but it is not a malware-removal technique and does not address active malicious processes or persistence mechanisms. A technician might choose this because malware sometimes hides in temp folders, but this step alone is not an appropriate first action in this scenario.

  • C. Incorrect.

    Incorrect. System Restore can sometimes help recover from recent system changes, but it is not the best first step when active malware is suspected. Malware may persist after a restore, and in some cases restore points may be infected or unavailable. Also, the scenario states that normal startup is unstable, making this less reliable as an initial response.

  • D. Incorrect.

    Incorrect. Ending processes in Task Manager during a normal boot might work for some unwanted applications, but in this case the system reboots shortly after loading, and the malware is likely launching automatically. This approach is less reliable than Safe Mode because the malicious process may start before the technician can stop it.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam