hardMultiple ChoiceObjective-mapped
220-1202 Practice Question: A technician is troubleshooting a user's slow…
A technician is troubleshooting a user's slow computer. The user mentions they received a call from 'Windows Support' saying their computer had a virus. The user gave the caller remote access to 'fix' it. Now, the computer is running slower and has strange pop-ups. What is the most likely consequence of this social engineering attack?
⚠ Common exam trap
CompTIA A+ often tests the distinction between generic malware effects (like botnet membership) and the specific, high-value goal of credential theft in social engineering scenarios, leading candidates to choose a broader but less precise answer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The attacker installed a keylogger to steal credentials and sensitive data.
The attacker gained remote access to the user's computer under the guise of tech support. Once in, they installed a keylogger to capture keystrokes, which is a common payload in such social engineering attacks. This allows the attacker to steal credentials, banking information, and other sensitive data, explaining the continued slow performance and pop-ups.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The computer is now part of a botnet used for DDoS attacks.
Why it's wrong here
While a computer compromised by malware *could* eventually become part of a botnet, the immediate symptoms of a slow computer and persistent pop-ups are more indicative of general adware or other resource-intensive malware directly impacting the user experience. Botnet activity often runs in the background, consuming resources for external attacks rather than generating overt user-facing issues like persistent pop-ups, unless the infection is particularly aggressive or poorly designed to conceal itself.
- ✓
The attacker installed a keylogger to steal credentials and sensitive data.
Why this is correct
A keylogger is a highly effective form of spyware designed to record every keystroke made on the compromised system. This allows an attacker to covertly capture sensitive information such as usernames, passwords, credit card numbers, and other personal data as the user types it. The exfiltrated data can then be used for identity theft, unauthorized financial transactions, or gaining access to other online accounts, directly leading to significant personal and financial compromise.
- ✗
The computer's BIOS has been corrupted.
Why it's wrong here
BIOS corruption is a severe hardware-level issue that typically prevents a computer from booting entirely or causes critical system instability, often requiring specialized recovery procedures or motherboard replacement. It is extremely rare for a remote access attack, which operates at the software level, to directly corrupt the BIOS firmware. The reported symptoms of a slow computer and pop-ups are characteristic of software-based malware, not a fundamental firmware failure.
- ✗
The hard drive has been physically damaged.
Why it's wrong here
Physical damage to a hard drive, such as a head crash or platter scratches, can only occur through mechanical failure or direct physical impact. Remote access attacks are purely software-based and cannot induce physical harm to hardware components. While malware can cause logical damage to data or file systems, it is fundamentally incapable of causing physical degradation or destruction of the hard drive itself, making this an incorrect diagnosis for a remote compromise.
Go deeper
Related to this question
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.