Courseiva
mediumMultiple ChoiceObjective-mapped

220-1202 Practice Question: A technician is cleaning a computer that has been…

A technician is cleaning a computer that has been infected with a rootkit. After running a standard antivirus scan, the malware is still detected on reboot. Which step should the technician take next to ensure complete removal?

⚠ Common exam trap

Test-takers frequently assume Safe Mode provides a clean environment for malware removal, but rootkits specifically target kernel-level persistence that persists even in Safe Mode, making a boot-time rescue disk the only reliable method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Boot from a rescue disk and run a malware scan.

Rootkits are designed to hide from the operating system and standard antivirus tools by intercepting system calls and loading before the OS security components. Booting from a rescue disk (e.g., a Linux live CD or a dedicated antivirus rescue ISO) bypasses the infected OS entirely, allowing the scanner to access the file system without the rootkit actively masking its presence. This ensures the malware cannot interfere with the scan, enabling complete detection and removal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Perform a clean installation of Windows.

    Why it's wrong here

    Performing a clean installation of Windows is a drastic measure that should be reserved as a last resort for severe, unresolvable malware infections. This process involves formatting the hard drive, which results in complete data loss and requires reinstalling all applications and reconfiguring user settings. While highly effective for malware eradication, it is exceptionally time-consuming and disruptive, making less invasive methods like rescue disk scans preferable as initial troubleshooting steps.

  • Boot from a rescue disk and run a malware scan.

    Why this is correct

    Booting from a rescue disk, also known as a bootable antivirus or recovery environment, loads a clean, trusted operating system directly from external media (USB or CD/DVD). This bypasses any malware, especially rootkits, that might be deeply embedded within the compromised installed operating system and actively hiding its presence or interfering with security software. Operating from an uninfected environment allows the malware scanner to access and remove malicious files and registry entries that would otherwise be protected or invisible.

  • Disable System Restore and run the antivirus again.

    Why it's wrong here

    Disabling System Restore is a recommended step during malware removal to prevent the infection from being restored from a previous restore point, and to allow the antivirus to clean files within those points. However, merely disabling it and rerunning an antivirus from within the potentially compromised operating system does not address the core issue of active, persistent malware like rootkits. Rootkits can still maintain control, hide their processes, and interfere with the antivirus's ability to detect and remove them effectively from the running system.

  • Run the antivirus in Safe Mode.

    Why it's wrong here

    Running an antivirus in Safe Mode is often a useful initial step for removing less sophisticated malware, as it loads only essential system drivers and services, potentially preventing some malware from loading. However, advanced or persistent threats, particularly certain types of rootkits, are specifically designed to load at a very low level and can still activate or hide their presence even in Safe Mode. This compromises the integrity of the scan, making it unreliable for thorough eradication compared to an external, trusted boot environment.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.