220-1102 Question 510
Single answerAntivirusA user reports that their Windows 11 laptop has become slow and repeatedly opens browser pop-ups, even when no browser window is active. You verify that the system has an antivirus product installed, but its definitions have not been updated in several weeks. The user needs the laptop for work later today, and company policy requires preserving user data whenever possible. Which action should the technician take FIRST to address the suspected malware issue?
- A
Boot the laptop normally and immediately start deleting suspicious files from the Downloads folder
- B
Update the antivirus signatures, then run a full system scan and quarantine any detected threats
- C
Reimage the laptop right away to guarantee that all malware is removed
- D
Disable System Restore and clear all browser caches before doing any malware scanning
Show answer and explanation
Correct answer: B
Explanation
The best first action is to update the antivirus signatures and run a full system scan. In a real support scenario, technicians should start with the least disruptive effective remediation method, especially when business continuity and data preservation matter. Outdated definitions significantly reduce the antivirus product's ability to detect current malware, so updating signatures is critical before scanning. After detection, threats should be quarantined rather than immediately deleted to reduce the risk of removing needed files and to allow review. If the malware cannot be removed successfully, the technician could escalate to additional steps such as scanning in Safe Mode or from rescue media, restoring from a known-good backup, or reimaging the device. This approach is consistent with common malware-removal best practices reflected in Windows security guidance and enterprise endpoint protection workflows.
- A. Incorrect.
This is not the best first action. Manually deleting files from Downloads may miss the actual infection source, especially if the malware is running from another location, has persistence mechanisms, or is fileless. It can also destroy evidence and does not follow best practice for structured malware remediation.
- B. Correct.
This is correct. A common first step in malware remediation is to ensure anti-malware definitions are current and then perform a full scan to detect and quarantine malicious software. Because the antivirus signatures are outdated, the installed product may not recognize current threats. Updating signatures before scanning improves detection accuracy and aligns with standard troubleshooting and security best practices.
- C. Incorrect.
Reimaging can be an effective last-resort remediation method, but it is not the best first step here. The scenario states that company policy requires preserving user data whenever possible, and the user needs the device later today. A full antivirus update and scan is less disruptive and is the appropriate initial response before moving to more destructive measures.
- D. Incorrect.
These tasks may sometimes be part of a broader cleanup process, but they should not come before updating and running antivirus scans. Disabling System Restore is sometimes performed in malware remediation workflows to prevent reinfection from restore points, but doing so first removes recovery options and does not directly identify or contain the malware. Clearing browser caches also does not address a likely active infection.