220-1102 Question 619
Single answerFake security warningsA user reports that their Windows 11 laptop suddenly displays repeated pop-up messages claiming the system is infected and instructing them to call a phone number immediately. The messages appear inside the web browser, the browser opens new tabs on its own, and the user says the warnings started after clicking a link in an email. Which action should the technician take FIRST to address this issue safely and effectively?
- A
Call the phone number in the warning to verify whether the alert is legitimate
- B
Close the browser, disconnect the device from the network, and run antimalware scans after checking for malicious browser extensions or notifications
- C
Enter the local administrator password into the pop-up so the browser can remove the detected threats
- D
Reinstall Windows immediately without attempting any containment or verification steps
Show answer and explanation
Correct answer: B
Explanation
This scenario describes a classic fake security warning or scareware event, often delivered through malicious websites, deceptive ads, browser notification abuse, or links in phishing emails. On A+ Core 2, the expected response is to recognize the social engineering aspect and avoid interacting with the warning. A technician should contain the issue first by closing the browser and disconnecting from the network if needed, then inspect browser extensions, notification permissions, startup behavior, and installed applications for adware or unwanted software. After that, run reputable, updated antimalware tools and clear browser data if appropriate. This approach aligns with common security best practices from Microsoft security guidance and general incident response principles: contain, identify, remediate, and verify. The key point is that browser-based infection claims and urgent phone-number prompts are strong indicators of a scam, not a legitimate security alert.
- A. Incorrect.
This is incorrect. Calling the number is a common social engineering trap used in fake security warning scams. Attackers use alarming messages to convince users to contact fraudulent support lines, disclose information, or pay for unnecessary services.
- B. Correct.
This is correct. Fake security warnings commonly originate from malicious websites, browser push notifications, scam pages, or adware rather than from a legitimate operating system alert. The safest first response is to stop interacting with the warning, close the browser if possible, disconnect the system from the network to limit further exposure, and then investigate for malicious browser extensions, site permissions, notifications, and adware before running updated antimalware scans.
- C. Incorrect.
This is incorrect. Legitimate security products do not ask users to enter administrative credentials into random browser pop-ups to clean infections. Providing credentials to such a prompt could give attackers access to the system or sensitive information.
- D. Incorrect.
This is incorrect. Reinstalling the operating system may remove malware, but it is not the first step in handling a suspected fake security warning. Best practice is to contain the issue, verify the source, remove malicious browser components or adware, and scan the system. Immediate reinstallation is excessive unless the system cannot be cleaned or is severely compromised.