220-1102 exam dumps

220-1102 practice question 607 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 607

Single answerApplication source/unofficial application stores

A user brings you an Android phone that has started showing constant pop-up ads and requesting unusual permissions after they installed a "premium streaming" app from a website linked in a forum post. The app is not available in the Google Play Store. The user asks how to avoid this problem in the future while still installing needed apps safely. Which recommendation is the BEST answer?

  1. A

    Disable Google Play Protect so it does not block apps from outside the Play Store

  2. B

    Install apps only from trusted, official application stores or verified vendor sources, and avoid sideloading from unknown websites

  3. C

    Root the phone so unwanted apps can be removed more easily after installation

  4. D

    Use any APK site as long as the app requests only storage permissions

Show answer and explanation

Correct answer: B

Explanation

This scenario tests recognition of the security risk posed by unofficial application stores and unknown sideloaded apps. For A+ Core 2, the key concept is that application source matters: official application stores generally provide screening, code signing, reputation checks, and update mechanisms that reduce risk compared with random third-party sites. On Android, Google documents using Google Play and Play Protect to help keep devices safer, while sideloading from unknown sources can expose users to malware, adware, and potentially unwanted applications. In enterprise and support contexts, the recommended guidance is to use official stores or verified publisher sources, keep security features enabled, and review permissions critically rather than assuming permissions alone determine safety.

  • A. Incorrect.

    Incorrect. Google Play Protect is a security feature that helps scan apps for potentially harmful behavior. Disabling it reduces protection and does not address the core risk of obtaining apps from untrusted sources. A user might choose this if they think security controls are merely inconvenient barriers to installation, but on A+ Core 2 the safer practice is to keep protective features enabled.

  • B. Correct.

    Correct. The best practice is to obtain applications from official stores such as Google Play or from verified, legitimate vendor sources when appropriate. Unofficial application stores and random download sites increase the risk of tampered, malicious, or repackaged apps. Avoiding unknown sideloaded APKs is the most effective recommendation to prevent recurrence of this issue.

  • C. Incorrect.

    Incorrect. Rooting a phone weakens the device's security model and can increase risk, not reduce it. While rooting may allow deeper access for troubleshooting, it is not an appropriate preventive recommendation for a standard user and is contrary to secure mobile device management best practices.

  • D. Incorrect.

    Incorrect. Permission scope alone does not prove an app is safe. Malicious apps may request limited permissions and still perform harmful actions, or they may misuse permissions in ways the user does not expect. The source of the application matters significantly; using "any APK site" is unsafe because unofficial repositories may host modified or malware-infected packages.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam