Courseiva
hardMultiple Choice

220-1202 Practice Question: A security analyst discovers that a user's…

A security analyst discovers that a user's workstation has been compromised by a rootkit that hides its processes from Task Manager. The rootkit is not detected by the installed antivirus. Which step is most effective for remediation?

⚠ Common exam trap

It's easy for candidates to assume Safe Mode or System Restore can bypass rootkit persistence, but CompTIA tests the understanding that rootkits operate below the OS layer and require a clean, offline environment to be reliably detected and removed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Boot from a rescue disk and perform an offline antivirus scan.

A rootkit that hides its processes from Task Manager and evades the installed antivirus operates at a deep level within the operating system, often in kernel mode. Booting from a rescue disk (e.g., a live CD/USB with an offline scanner) loads a clean operating system environment, preventing the rootkit from loading and allowing the antivirus to scan the infected system's files without interference. This offline approach is the most effective remediation step when the rootkit is actively hiding from the installed AV in the normal OS context.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a full antivirus scan in Safe Mode.

    Why it's wrong here

    Safe Mode loads only core drivers, so many rootkits still load and remain hidden; the antivirus also lacks signatures for this rootkit, so the scan finds nothing. Safe Mode scanning suits malware that runs only in normal mode, not kernel-level rootkits concealing processes.

  • ✗

    Use System Restore to revert to a previous state.

    Why it's wrong here

    System Restore only reverts registry, drivers and system files; it leaves user data and any rootkit components outside those snapshots intact, so the infection persists. It suits recovering from a faulty driver or update, not removing malware that has modified the running kernel.

  • ✓

    Boot from a rescue disk and perform an offline antivirus scan.

    Why this is correct

    A rootkit hiding processes from Task Manager operates at kernel level, so the running antivirus cannot see it. Booting from a rescue disk mounts the system offline, exposing the dormant rootkit files to scanning without the compromised kernel interfering, which is why offline remediation is effective.

  • ✗

    Reinstall the operating system from the recovery partition.

    Why it's wrong here

    Reinstalling from the recovery partition restores the vendor image but may reapply compromised files if the partition itself was modified, and it is not the most effective first step. Recovery-partition reimaging suits corrupted system files or failed upgrades, not confirmed rootkit eradication.

About these practice questions

This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.