220-1102 exam dumps

220-1102 practice question 503 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 503

Single answerPattern

A small business reports that several Windows 11 PCs are displaying pop-ups claiming the systems are infected and urging users to call a phone number. On one affected PC, the technician notices the browser opens unknown tabs at startup, security software has been disabled, and multiple users began seeing the issue after downloading a free PDF converter from the same website. The IT manager wants to identify the attack pattern so the team can apply the correct response across all affected systems. Which pattern BEST matches this scenario?

  1. A

    A phishing campaign delivered through email attachments

  2. B

    A rogue antivirus/malware infection introduced through bundled software

  3. C

    A brute-force attack against local administrator accounts

  4. D

    A denial-of-service attack targeting the company's internet connection

Show answer and explanation

Correct answer: B

Explanation

The best answer is rogue antivirus/malware infection introduced through bundled software. In A+ Core 2, candidates are expected to recognize common malware patterns from symptoms and user behavior, not just memorize definitions. Scareware and rogue antivirus commonly generate alarming but fraudulent infection messages, may alter browser behavior, and often arrive through deceptive downloads, fake utilities, or bundled installers. Best practice is to isolate affected systems from the network, identify and remove malicious applications, update and run trusted antimalware tools, verify startup items and browser settings, and review whether additional malware was installed. This aligns with standard malware remediation guidance and CompTIA's emphasis on identifying symptoms, determining the probable cause, and implementing appropriate corrective action.

  • A. Incorrect.

    This is incorrect. Phishing often begins with deceptive email messages, links, or attachments intended to trick users into revealing credentials or launching malware. In this scenario, the common pattern is users installing the same free utility from a website, followed by fake infection alerts and disabled security controls. That behavior aligns more closely with malware delivered through software bundling than with a traditional phishing email campaign.

  • B. Correct.

    This is correct. Fake infection warnings, pressure to call a number, browser hijacking behavior, and disabled security tools are classic indicators of rogue antivirus/scareware or related malware. The fact that multiple users downloaded the same free application suggests a repeated infection pattern through bundled or trojanized software. Recognizing this pattern helps the technician respond appropriately by isolating systems, removing the malicious software, scanning for additional payloads, and educating users about untrusted downloads.

  • C. Incorrect.

    This is incorrect. A brute-force attack involves repeated login attempts to guess passwords, usually resulting in account lockouts, authentication failures, or suspicious sign-in activity. It does not typically cause fake antivirus pop-ups, browser tabs opening at startup, or end-user scare messages directing users to call a support number.

  • D. Incorrect.

    This is incorrect. A denial-of-service attack is intended to overwhelm a service or network resource, causing slowdowns or outages. It would not normally present as pop-up infection messages on local PCs, browser hijacking, or disabled endpoint security on multiple workstations after software installation.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam