220-1202 Software Troubleshooting Practice Question
A technician is troubleshooting a Windows 10 workstation that is exhibiting symptoms of a malware infection. The technician has already disconnected the computer from the network. Which of the following should the technician do next to remediate the infection? (Choose two.)
⚠ Common exam trap
The trap here is choosing reimaging or user education as immediate remediation steps, when they are either too drastic or do not address the active infection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a full antivirus scan using updated definitions.
After isolating the infected system, the technician should run a full antivirus scan with updated definitions to detect and remove malware. Additionally, booting into Safe Mode and using specialized removal tools helps eliminate persistent infections that might resist normal removal. These two actions directly address the malware, while other options are either preventive, premature, or not directly remedial.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable System Restore and create a restore point.
Why it's wrong here
Creating a restore point after infection is not helpful because the restore point would include the malware. System Restore is useful for reverting to a pre-infection state, but only if a clean restore point exists. Enabling it now does not remediate the current infection.
- ✓
Run a full antivirus scan using updated definitions.
Why this is correct
After isolating the system, running a full antivirus scan with the latest definitions is essential to detect and remove malware. Updated definitions ensure the scanner recognizes current threats. This step is a core part of malware remediation and should be performed before restoring network access.
- ✓
Boot into Safe Mode and run additional malware removal tools.
Why this is correct
Safe Mode loads only essential services, preventing many malware programs from running. This makes it easier to remove them with specialized tools. Running additional removal tools in Safe Mode increases the chance of completely eradicating the infection, especially for persistent malware.
- ✗
Reimage the computer immediately without attempting removal.
Why it's wrong here
Reimaging is a drastic step that should be considered only if removal efforts fail or if the infection is severe. It erases all data and requires reinstalling applications. Attempting removal first is less disruptive and often sufficient. Reimaging without trying other methods is premature.
- ✗
Educate the user on safe browsing habits.
Why it's wrong here
User education is important for prevention but does not remediate an existing infection. It should be done after the malware is removed. The immediate next steps should focus on eliminating the malware, not on training, which can be addressed later.
Go deeper
Related to this question
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.