Courseiva
hardMultiple ChoiceObjective-mapped

220-1202 Practice Question: A user's browser is infected with a malicious…

A user's browser is infected with a malicious extension that steals credentials. The extension was installed via a drive-by download from a compromised website. After removing the extension, what additional step should you take to ensure the credentials are not compromised?

⚠ Common exam trap

CompTIA often tests the misconception that removing the malicious component or clearing local data is sufficient, when in fact the attacker already has the stolen credentials and only changing passwords remediates the actual compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Change all passwords that were entered while the extension was active

A malicious browser extension that steals credentials has already exfiltrated any passwords entered while it was active. Removing the extension stops further theft, but the compromised credentials remain exposed. Changing all passwords ensures that stolen credentials are invalidated, preventing unauthorized access to accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Clear the browser cache and cookies

    Why it's wrong here

    Clearing the browser cache and cookies primarily removes temporary website data, stored session information, and user preferences. While this action can resolve certain browsing issues or privacy concerns, it does not address the fundamental problem of a malicious extension that may have already captured and exfiltrated user credentials. The cache and cookies do not store passwords in a format that, if cleared, would invalidate previously stolen login information, leaving compromised accounts vulnerable.

  • Run a full antivirus scan

    Why it's wrong here

    Running a full antivirus scan is a crucial step for detecting and removing malware from a system, including potentially the malicious browser extension itself or other co-existing threats. However, an antivirus scan's primary function is to identify and eradicate malicious software, not to revoke or modify credentials that have already been intercepted and transmitted by the extension to an attacker. Therefore, while beneficial for system hygiene, it does not directly mitigate the risk of unauthorized access to accounts using stolen passwords.

  • Reset the browser settings to default

    Why it's wrong here

    Resetting the browser settings to default effectively disables or removes installed extensions, clears temporary data, and restores the browser's configuration to its original state. This action is highly effective at eliminating the malicious extension and preventing any further credential harvesting. Nevertheless, resetting the browser does not undo the damage already done; any passwords that were captured and exfiltrated by the extension before the reset remain compromised, necessitating further action to secure those accounts.

  • Change all passwords that were entered while the extension was active

    Why this is correct

    Changing all passwords that were entered while the malicious extension was active is the most critical and direct action to mitigate the immediate risk of unauthorized account access. Malicious browser extensions designed for credential harvesting often log keystrokes, intercept form submissions, or read data from web pages. By changing these passwords, the user invalidates any credentials that the extension may have already captured and transmitted, thereby preventing attackers from using the stolen information to log into affected accounts.

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.