220-1102 exam dumps

220-1102 practice question 470 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 470

Single answer10. Educate the end user

A user in the accounting department reports that a pop-up appeared on her workstation claiming her files were encrypted and instructing her to call a phone number immediately. You verify that the message was a scareware-style browser pop-up and that no files were actually encrypted. After removing the malicious browser extension and restoring the browser settings, the user asks what she should do if this happens again. Which response is the BEST end-user education to provide?

  1. A

    Tell the user to call the number in the warning so the issue can be resolved quickly if it happens again

  2. B

    Tell the user to close the browser tab or browser, avoid interacting with the pop-up, and report the incident to IT immediately

  3. C

    Tell the user to disable antivirus notifications so future warnings are less confusing

  4. D

    Tell the user to restart the PC and continue working without reporting it if the message disappears

Show answer and explanation

Correct answer: B

Explanation

This question tests the A+ Core 2 objective of educating the end user after a security-related incident. In real environments, technicians are expected not only to resolve issues but also to coach users on safer behavior. Best practice is to instruct users not to click suspicious links, not to call phone numbers displayed in unsolicited warnings, not to provide credentials or payment information, and to report suspicious activity to IT immediately. This reflects standard security awareness guidance from organizations such as CISA and Microsoft, which advise users to treat unexpected browser alerts and tech support warnings as suspicious and to report them through approved channels. The key applied skill here is choosing the response that reduces future risk while supporting organizational incident response procedures.

  • A. Incorrect.

    This is incorrect. Scareware and tech support scam pop-ups commonly instruct users to call a fraudulent support number. End-user education should specifically warn users not to call, click, or interact with such messages. Calling the number can lead to social engineering, unnecessary payments, or remote access by attackers.

  • B. Correct.

    This is correct. The best user guidance is to avoid interacting with the suspicious message, close the tab or browser if possible, and notify IT or the security team. This aligns with common security awareness practices: do not click suspicious pop-ups, do not call listed numbers, and report the event promptly so the organization can investigate and document it.

  • C. Incorrect.

    This is incorrect. Antivirus and security notifications help protect the system and should not be disabled to reduce confusion. The better approach is to educate the user on how to distinguish legitimate security alerts from fraudulent browser pop-ups and to contact IT when uncertain.

  • D. Incorrect.

    This is incorrect. Although restarting may clear a temporary browser pop-up in some cases, telling the user not to report the incident is poor security practice. IT should be informed so they can verify whether the event was merely a scam pop-up or part of a larger issue, such as malicious extensions, adware, or credential harvesting attempts.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam