mediumMultiple Choice
220-1202 Practice Question: That their Windows 10 PC is infected with malware…
A user reports that their Windows 10 PC is infected with malware that prevents the Task Manager from opening. You need to terminate a suspicious process from the command line. Which command should you use to forcefully end a process by its name?
⚠ Common exam trap
Many exam-takers confuse `tasklist` (which only lists processes) with `taskkill` (which terminates them), or mistakenly think `shutdown` or `regedit` can end a single process, leading them to choose a non-terminating command.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
taskkill /IM malware.exe /F
The `taskkill` command with the `/IM` (image name) parameter targets a process by its executable name, and the `/F` flag forcefully terminates it. This is the appropriate tool when Task Manager is disabled by malware, as it directly ends the process from the command line without relying on GUI interaction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
tasklist /v
Why it's wrong here
tasklist /v only enumerates running processes with verbose detail such as user context and window titles; it cannot terminate anything. It is tempting because it identifies the suspicious process name you would then feed to taskkill /f /im, but listing alone leaves the malware running.
- ✓
taskkill /IM malware.exe /F
Why this is correct
taskkill with /IM targets the process by image name and /F forces termination, bypassing the graceful close that malware may block. Running it from an elevated command prompt kills the suspicious process even when Task Manager is disabled.
- ✗
shutdown /r /t 0
Why it's wrong here
'shutdown /r /t 0' restarts the machine immediately; it terminates no named process and would close the command session. It is tempting as a forceful recovery action, but taskkill /f /im is the command that ends a process by image name.
- ✗
regedit /e backup.reg
Why it's wrong here
regedit /e exports a registry hive to a .reg file for backup or inspection; it never terminates processes. It is tempting as a forensic step to capture the malware's persistence keys before remediation, but the scenario demands forceful process termination, which taskkill /f /im provides.
Go deeper
Related to this question
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.