hardMultiple ChoiceObjective-mapped
220-1202 Practice Question: A user's browser is infected with a malicious…
A user's browser is infected with a malicious extension that steals credentials. The extension was installed via a drive-by download from a compromised website. After removing the extension, what additional step should you take to ensure the credentials are not compromised?
⚠ Common exam trap
CompTIA often tests the misconception that removing the malicious component or clearing local data is sufficient, when in fact the attacker already has the stolen credentials and only changing passwords remediates the actual compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change all passwords that were entered while the extension was active
A malicious browser extension that steals credentials has already exfiltrated any passwords entered while it was active. Removing the extension stops further theft, but the compromised credentials remain exposed. Changing all passwords ensures that stolen credentials are invalidated, preventing unauthorized access to accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Clear the browser cache and cookies
Why it's wrong here
Clearing the browser cache and cookies primarily removes temporary website data, stored session information, and user preferences. While this action can resolve certain browsing issues or privacy concerns, it does not address the fundamental problem of a malicious extension that may have already captured and exfiltrated user credentials. The cache and cookies do not store passwords in a format that, if cleared, would invalidate previously stolen login information, leaving compromised accounts vulnerable.
- ✗
Run a full antivirus scan
Why it's wrong here
Running a full antivirus scan is a crucial step for detecting and removing malware from a system, including potentially the malicious browser extension itself or other co-existing threats. However, an antivirus scan's primary function is to identify and eradicate malicious software, not to revoke or modify credentials that have already been intercepted and transmitted by the extension to an attacker. Therefore, while beneficial for system hygiene, it does not directly mitigate the risk of unauthorized access to accounts using stolen passwords.
- ✗
Reset the browser settings to default
Why it's wrong here
Resetting the browser settings to default effectively disables or removes installed extensions, clears temporary data, and restores the browser's configuration to its original state. This action is highly effective at eliminating the malicious extension and preventing any further credential harvesting. Nevertheless, resetting the browser does not undo the damage already done; any passwords that were captured and exfiltrated by the extension before the reset remain compromised, necessitating further action to secure those accounts.
- ✓
Change all passwords that were entered while the extension was active
Why this is correct
Changing all passwords that were entered while the malicious extension was active is the most critical and direct action to mitigate the immediate risk of unauthorized account access. Malicious browser extensions designed for credential harvesting often log keystrokes, intercept form submissions, or read data from web pages. By changing these passwords, the user invalidates any credentials that the extension may have already captured and transmitted, thereby preventing attackers from using the stolen information to log into affected accounts.
Go deeper
Related to this question
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.