Courseiva
mediumMultiple Choice

220-1202 Practice Question: A security incident occurred where an attacker…

A security incident occurred where an attacker modified a PowerShell script on a file server to include malicious commands. The script is executed daily by a scheduled task. Which scripting security best practice could have prevented this attack?

⚠ Common exam trap

Many exam-takers choose 'Set the script file to read-only' because they think file permissions alone are sufficient, but CompTIA tests that integrity verification (via digital signatures) is the only way to detect unauthorized modifications in a script that is executed automatically.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a digital signature to sign the script and enforce execution policy

Enforcing an execution policy that requires scripts to be digitally signed ensures that only scripts signed by a trusted publisher can run. If the attacker modified the script, the digital signature would become invalid, and the execution policy would block the script from running, preventing the malicious commands from executing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the script in a hidden folder

    Why it's wrong here

    Hiding a folder changes only its display attribute; the file remains fully accessible by path and can be modified exactly as before. It is tempting because obscurity reduces casual discovery, and hidden folders are legitimately used to declutter shares, but they provide no access control or integrity protection.

  • ✗

    Set the script file to read-only

    Why it's wrong here

    A read-only attribute is trivially cleared by any account with write or ownership rights on the file, so an attacker can remove it, edit the script, and restore it. It is tempting because read-only flags deter accidental edits, and setting one is reasonable when protecting configuration files from routine user changes.

  • ✓

    Use a digital signature to sign the script and enforce execution policy

    Why this is correct

    Signing the script with a code-signing certificate and enforcing an AllSigned execution policy makes PowerShell reject any tampered or unsigned script before it runs. An attacker modifying the scheduled script invalidates the signature, so the daily task fails safely instead of executing malicious commands.

  • ✗

    Compile the script into an executable

    Why it's wrong here

    Compiling to an executable does not prevent tampering with the source or binary on disk, and the scheduled task would still run whatever file replaced it. It is tempting because compilation obscures code from casual reading, which is useful for protecting intellectual property, but it provides no integrity verification against modification.

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.