mediumMultiple Choice
220-1202 Practice Question: A security incident occurred where an attacker…
A security incident occurred where an attacker modified a PowerShell script on a file server to include malicious commands. The script is executed daily by a scheduled task. Which scripting security best practice could have prevented this attack?
⚠ Common exam trap
Many exam-takers choose 'Set the script file to read-only' because they think file permissions alone are sufficient, but CompTIA tests that integrity verification (via digital signatures) is the only way to detect unauthorized modifications in a script that is executed automatically.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a digital signature to sign the script and enforce execution policy
Enforcing an execution policy that requires scripts to be digitally signed ensures that only scripts signed by a trusted publisher can run. If the attacker modified the script, the digital signature would become invalid, and the execution policy would block the script from running, preventing the malicious commands from executing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the script in a hidden folder
Why it's wrong here
Hiding a folder changes only its display attribute; the file remains fully accessible by path and can be modified exactly as before. It is tempting because obscurity reduces casual discovery, and hidden folders are legitimately used to declutter shares, but they provide no access control or integrity protection.
- ✗
Set the script file to read-only
Why it's wrong here
A read-only attribute is trivially cleared by any account with write or ownership rights on the file, so an attacker can remove it, edit the script, and restore it. It is tempting because read-only flags deter accidental edits, and setting one is reasonable when protecting configuration files from routine user changes.
- ✓
Use a digital signature to sign the script and enforce execution policy
Why this is correct
Signing the script with a code-signing certificate and enforcing an AllSigned execution policy makes PowerShell reject any tampered or unsigned script before it runs. An attacker modifying the scheduled script invalidates the signature, so the daily task fails safely instead of executing malicious commands.
- ✗
Compile the script into an executable
Why it's wrong here
Compiling to an executable does not prevent tampering with the source or binary on disk, and the scheduled task would still run whatever file replaced it. It is tempting because compilation obscures code from casual reading, which is useful for protecting intellectual property, but it provides no integrity verification against modification.
Go deeper
Related to this question
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.