220-1102 Question 606
Single answerSecurity concernsA small accounting office reports that several Windows 11 PCs suddenly display browser pop-ups claiming the systems are infected and prompting users to call a support number. Users also report that the browser homepage changed without approval and that performance has become noticeably slower. The technician confirms that antivirus definitions are current and no major OS files appear to be damaged. Which action should the technician take FIRST to address the most likely security issue?
- A
Run anti-malware and antivirus scans, then remove suspicious browser extensions and unwanted programs
- B
Replace the hard drives in all affected PCs because the systems are likely suffering from hardware failure
- C
Reimage each PC immediately without attempting any remediation steps
- D
Disable User Account Control so users can manually uninstall anything they do not recognize
Show answer and explanation
Correct answer: A
Explanation
This scenario reflects a common A+ Core 2 security concern: scareware/adware/PUP infection. Fake infection alerts, browser redirects, unauthorized homepage changes, and degraded performance are classic indicators. The best first action is to perform malware remediation using current security tools and to inspect/remove suspicious extensions and installed applications. This aligns with standard security best practices such as isolating symptoms, scanning with updated tools, removing malicious software, and escalating to more invasive recovery steps only if necessary. Microsoft security guidance and common endpoint protection workflows support scanning, reviewing startup items/extensions, and removing unwanted software before reimaging when the system is still operational and signs point to nuisance malware rather than catastrophic compromise.
- A. Correct.
Correct. The symptoms point to scareware and potentially unwanted programs (PUPs), often accompanied by malicious browser extensions or adware. A practical first response is to run updated anti-malware/antivirus scans, review installed applications, and remove suspicious add-ons or software. This matches standard malware-removal best practices for end-user systems before taking more disruptive action.
- B. Incorrect.
Incorrect. Hardware failure does not typically cause fake infection pop-ups, browser hijacking, or unauthorized homepage changes. These symptoms are much more consistent with adware, scareware, or other malware-related issues rather than failing storage devices.
- C. Incorrect.
Incorrect. Reimaging can be appropriate if remediation fails or if compromise is severe, but it is not the best first step here. The scenario describes common nuisance-malware behavior, and standard troubleshooting begins with identification and removal of malicious software before resorting to a full wipe.
- D. Incorrect.
Incorrect. Disabling User Account Control reduces system security and makes it easier for unwanted software to make additional changes. UAC is a protection mechanism, not an obstacle that should be removed during a malware event.