Courseiva
hardMultiple Choice

220-1202 Practice Question: After a security incident, a Windows 10…

After a security incident, a Windows 10 workstation is suspected of having malware that prevents the Task Manager and Command Prompt from opening. You need to run a system scan. Which tool can you use from the Windows Recovery Environment (WinRE) to perform an offline antivirus scan?

⚠ Common exam trap

Candidates often confuse system repair tools (like SFC) with antivirus tools, or assuming that any command-line tool in WinRE can perform an offline scan; candidates must recognize that only Microsoft Defender Offline is specifically designed for offline malware removal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Defender Offline Scan

Microsoft Defender Offline Scan is designed to run from the Windows Recovery Environment (WinRE) to scan the system before Windows starts, which bypasses malware that blocks tools like Task Manager or Command Prompt. It uses the same antivirus engine as Windows Defender but runs in a pre-boot environment, allowing it to detect and remove persistent threats that load early or hide from the normal OS. This makes it the correct tool for an offline antivirus scan when the system is suspected of being compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    System File Checker (sfc /scannow /offbootdir=C:\ /offwindir=C:\Windows)

    Why it's wrong here

    System File Checker (SFC) is designed to scan for and restore corrupted Windows system files by comparing them against known good versions stored in the component store. While it can be run offline using the specified parameters, SFC lacks any malware detection capabilities, signature databases, or heuristic analysis engines required to identify and remove malicious software. Its function is strictly system file integrity, not antivirus protection.

  • ✗

    Windows Memory Diagnostic

    Why it's wrong here

    Windows Memory Diagnostic is a utility specifically engineered to test the physical Random Access Memory (RAM) modules for hardware defects or errors. It performs a series of intensive tests to identify issues that could lead to system crashes or data corruption. This tool is entirely focused on hardware diagnostics and possesses no functionality whatsoever for detecting, scanning for, or removing software-based threats like malware, rendering it irrelevant to a security incident.

  • ✓

    Microsoft Defender Offline Scan

    Why this is correct

    Microsoft Defender Offline Scan is an essential tool for addressing persistent or deeply embedded malware infections, such as rootkits. It reboots the system into a secure, minimal environment, typically Windows Recovery Environment (WinRE), where it can perform a comprehensive scan using the latest virus definitions without loading the potentially compromised Windows operating system. This isolation prevents malware from actively interfering with the scanning process, allowing for more effective detection and removal of sophisticated threats.

  • ✗

    Diskpart

    Why it's wrong here

    Diskpart is a command-line utility used for managing disk partitions, volumes, and storage devices. Its primary functions include creating, deleting, formatting, and resizing partitions, as well as assigning drive letters and managing storage pools. While crucial for disk management tasks, Diskpart operates at a low level of disk organization and possesses no features for detecting, analyzing, or removing malicious software, making it unsuitable for addressing a security incident.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.