220-1102 exam dumps

220-1102 practice question 628 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 628

Single answerMissing/renamed files

A user reports that several Word and Excel files in their Documents folder suddenly have unfamiliar names and no longer open normally. One file that used to be named Budget.xlsx is now named Budget.xlsx.locked, and the user says the issue appeared after opening an unexpected email attachment earlier that morning. The user can still see the files, but they appear to be inaccessible. What is the MOST likely cause of this issue?

  1. A

    The files were hidden by a file attribute change and need hidden items enabled in File Explorer

  2. B

    The files were encrypted and renamed by ransomware after the malicious attachment was opened

  3. C

    The user accidentally changed the default application associated with Office documents

  4. D

    Windows moved the files into a temporary profile because the user signed in with a corrupted account

Show answer and explanation

Correct answer: B

Explanation

The best answer is that the files were encrypted and renamed by ransomware. In real-world support scenarios, technicians should recognize common ransomware indicators: files are still present, filenames are modified or given an unfamiliar extension, and users often report the issue starting after opening a suspicious attachment or link. CompTIA A+ Core 2 expects candidates to identify malware symptoms and respond appropriately. Best practice is to isolate the system from the network, inform security personnel or follow the incident response process, and restore data from known-good backups if available. Microsoft and CISA guidance on ransomware both emphasize suspicious attachments as a common infection vector and note file renaming/encryption as a typical symptom.

  • A. Incorrect.

    Incorrect. Hidden files typically disappear from normal view until hidden items are enabled, but in this scenario the files are still visible and have been renamed with an added extension such as .locked. A hidden attribute change does not normally rename files or prevent them from opening in this way.

  • B. Correct.

    Correct. A common sign of ransomware is that user files remain present but are renamed, often with an unfamiliar extension, and become unreadable because they have been encrypted. The timeline also fits: the problem began after the user opened a suspicious email attachment, which is a frequent ransomware delivery method.

  • C. Incorrect.

    Incorrect. Changing the default application association can cause files to open with the wrong program or produce an 'Open with' prompt, but it does not typically rename files or append a new extension like .locked. The files becoming inaccessible after a suspicious attachment points to malicious encryption rather than an application-association problem.

  • D. Incorrect.

    Incorrect. A temporary profile or corrupted user profile can make files appear missing from expected folders because Windows loads a different profile path. However, it would not typically rename existing documents by appending an extension such as .locked. The files being visible but unreadable is more consistent with ransomware behavior.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam