220-1102 exam dumps

220-1102 practice question 532 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 532

Single answerThird-party vendor

A company's help desk begins receiving reports that users are seeing unexpected browser pop-ups and a new toolbar after installing a free PDF utility from the internet. The utility is made by a third-party vendor and is not on the company's approved software list. Antivirus scans do not detect any malware, but the pop-ups continue and several users report their browser home page has changed. What should the technician do FIRST?

  1. A

    Remove the application and associated browser add-ons, then document the incident and recommend using only approved software

  2. B

    Reimage every affected computer immediately because any third-party software change indicates a full compromise

  3. C

    Disable the users' network accounts until the vendor confirms whether the utility is legitimate

  4. D

    Add the vendor's installer to the antivirus allow list so future installations are not blocked

Show answer and explanation

Correct answer: A

Explanation

This question tests practical handling of unapproved third-party vendor software in a support environment. On CompTIA A+ Core 2, technicians are expected to recognize that third-party applications can introduce security and usability issues even when traditional antivirus does not detect them as malware. Browser hijacking behavior, unwanted toolbars, pop-ups, and home-page changes are classic signs of PUP/PUA-style bundled software. Best practice is to remove the unauthorized application and any related browser components, document the incident, and enforce the organization's approved software policy or acceptable use policy. If symptoms persist after removal, additional steps such as malware remediation, browser reset, or reimaging may be needed. This aligns with standard endpoint security practices such as application control, least privilege, and software approval processes commonly recommended in enterprise IT environments.

  • A. Correct.

    Correct. In an A+ Core 2 context, unexpected pop-ups, browser home-page changes, and toolbars after installing unapproved software strongly suggest potentially unwanted applications (PUA/PUP) or bundled adware from a third-party vendor. The best first step is to remove the unauthorized software and related browser extensions or add-ons, document what happened, and reinforce approved-software policy. This is a practical first response before escalating to more disruptive actions.

  • B. Incorrect.

    Incorrect. Reimaging may be appropriate if the system remains unstable or infected after remediation, but it is not the best first step in this scenario. The symptoms point to bundled adware or a PUP rather than clear evidence of a full system compromise requiring immediate rebuild of every affected device.

  • C. Incorrect.

    Incorrect. Disabling user accounts is generally reserved for suspected account compromise, malicious insider activity, or active credential abuse. Here, the issue is unauthorized software from a third-party vendor affecting browsers, not evidence that the users' identities or accounts have been compromised.

  • D. Incorrect.

    Incorrect. Allow-listing the installer would worsen the problem by permitting more unauthorized installations. Even if the utility itself has a legitimate use, it is not approved software and appears to include unwanted bundled components. Best practice is to block or remove unapproved third-party applications rather than exempt them from security controls.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam