220-1102 exam dumps

220-1102 practice question 610 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 610

Single answerUnauthorized/malicious application

A user reports that their Windows 11 laptop has become very slow and displays frequent pop-up messages claiming the system is infected. The user says the messages started shortly after installing a free "PC cleanup" utility from a website found through a search engine. The security team confirms the application is not approved software. Which action should the technician take FIRST to address this unauthorized or malicious application?

  1. A

    Run the vendor's built-in uninstaller for the cleanup utility

  2. B

    Disconnect the laptop from the network and begin malware remediation procedures

  3. C

    Upgrade the system RAM to improve performance while troubleshooting

  4. D

    Disable User Account Control so the application can be removed without prompts

Show answer and explanation

Correct answer: B

Explanation

This scenario describes a likely rogue application or scareware/PUA that was installed from an untrusted source and is now generating fake infection warnings and degrading performance. In A+ Core 2, technicians are expected to prioritize containment when malware is suspected. Disconnecting the system from the network is an appropriate first step before proceeding with malware remediation. After isolation, best practice is to quarantine or disable the threat, update anti-malware signatures, run scans, remove or remediate the infection, reboot if needed, and educate the user to avoid installing unapproved software. This aligns with standard guidance from Microsoft security documentation and common incident response principles: contain first, then eradicate and recover.

  • A. Incorrect.

    Incorrect. Although uninstalling the program may eventually be part of cleanup, using the application's own uninstaller first is not the best initial response when the software is suspected to be malicious or rogue security software. Malicious applications may leave behind persistence mechanisms, install additional components, or attempt to evade removal.

  • B. Correct.

    Correct. When a system shows signs of a potentially malicious or unauthorized application, the first priority is containment. Disconnecting the device from the network helps prevent further communication with malicious servers, data exfiltration, lateral movement, or additional payload downloads. After containment, the technician should follow malware remediation best practices such as identifying and removing the threat, updating anti-malware tools, rescanning, and validating system integrity.

  • C. Incorrect.

    Incorrect. Adding RAM does not address the root cause. Performance issues in this scenario are consistent with rogue or malicious software, not a hardware capacity problem. This option reflects a common mistake of treating symptoms instead of the likely security issue.

  • D. Incorrect.

    Incorrect. Disabling User Account Control reduces security and is not an appropriate response. UAC helps prevent unauthorized system changes. Lowering protections to remove suspicious software increases risk and goes against standard security best practices.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam