Courseiva
mediumMultiple Choice

220-1202 Practice Question: A user calls the help desk because their computer…

A user calls the help desk because their computer is running slowly and they see a fake antivirus program warning that their system is infected. The user cannot close the warning window. Which type of malware is this, and what is the best removal approach?

⚠ Common exam trap

CompTIA A+ often tests the distinction between ransomware and rogue antivirus, trapping candidates who confuse the 'pay to remove' demand with ransomware's file-encryption extortion, when the key difference is that rogue antivirus does not actually encrypt files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rogue antivirus; boot into Safe Mode with Networking and run Malwarebytes.

The symptoms—a fake antivirus warning that cannot be closed—are classic indicators of rogue antivirus (scareware). This type of malware mimics legitimate security software to trick users into paying for unnecessary services. The best removal approach is to boot into Safe Mode with Networking, which loads only essential drivers and services, preventing the rogue program from auto-starting, then run Malwarebytes to detect and remove the threat.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ransomware; pay the fee to remove the warning.

    Why it's wrong here

    Ransomware encrypts files and demands payment; this stem describes a fake alert, and paying never removes malware. Payment is only ever considered, and discouraged, after genuine encryption with a verified ransom demand and no viable backup.

  • ✗

    Spyware; run a full scan in normal mode.

    Why it's wrong here

    Spyware covertly collects user activity and does not present fake antivirus warnings or block window closure, so a normal-mode scan misdiagnoses it and may leave the active rogue process running. Spyware scanning is correct when investigating data exfiltration or keystroke logging.

  • ✓

    Rogue antivirus; boot into Safe Mode with Networking and run Malwarebytes.

    Why this is correct

    Rogue antivirus masquerades as legitimate security software, using scareware pop-ups that resist normal window closure to pressure payment. Booting into Safe Mode with Networking prevents the rogue's startup persistence from loading, allowing Malwarebytes to quarantine the infection and its associated registry entries without interference from the running process.

  • ✗

    Adware; uninstall the program from Control Panel.

    Why it's wrong here

    Adware displays unwanted advertisements; it does not lock a window with fake infection alerts, and Control Panel removal cannot clear a running rogue process. Adware removal via Control Panel is correct for persistent pop-up advertising without system-wide infection symptoms.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.