hardMultiple ChoiceObjective-mapped
220-1202 Practice Question: During a routine security audit, a technician…
During a routine security audit, a technician discovers that a user's computer has a program that opens a backdoor on port 4444 and allows remote control. The program was installed alongside a free PDF converter the user downloaded last week. Which malware type is this, and what is the most effective removal method?
⚠ Common exam trap
The A+ exam often tests the distinction between a Trojan horse and a worm by emphasizing that a Trojan requires user action to install, whereas a worm spreads autonomously, leading candidates to incorrectly choose 'worm' when they see a backdoor on a specific port.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trojan horse; boot into Safe Mode and run a full anti-malware scan.
The program is a Trojan horse because it disguises itself as a legitimate PDF converter while secretly installing a backdoor. The most effective removal method is to boot into Safe Mode, which loads only essential drivers and services, preventing the Trojan from running, and then perform a full anti-malware scan to detect and remove the malicious files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Worm; use a network-based firewall to block port 4444.
Why it's wrong here
A worm is a self-replicating malware that spreads autonomously across networks, often exploiting vulnerabilities. While blocking a specific port like 4444 might prevent further network propagation or command-and-control (C2) communication if that port is utilized by the worm, it does not remove the worm already resident and active on the infected system. The primary action for an existing worm infection is detection and complete eradication, not merely network containment.
- ✓
Trojan horse; boot into Safe Mode and run a full anti-malware scan.
Why this is correct
A Trojan horse is a type of malware that masquerades as legitimate software, often bundled with freeware, to trick users into installing it. Once executed, it performs malicious activities, such as opening backdoors for remote access. Booting into Safe Mode loads only essential system services and drivers, preventing the Trojan from fully executing or hiding its processes, thereby making it more vulnerable to detection and removal by a full anti-malware scan.
- ✗
Ransomware; pay the ransom to regain control.
Why it's wrong here
Ransomware primarily operates by encrypting a user's files or locking them out of their system, subsequently demanding a ransom payment for decryption keys or access restoration. The described scenario, involving a program opening a backdoor, is characteristic of a Trojan or a remote access tool, not the file-encryption behavior typical of ransomware. Furthermore, paying the ransom is generally discouraged by cybersecurity experts as it does not guarantee file recovery and incentivates further malicious attacks.
- ✗
Rootkit; perform a clean installation of Windows.
Why it's wrong here
A rootkit is designed to conceal its presence and the presence of other malicious software, often operating at a deep system level to evade detection. While a clean installation of Windows is a definitive method to remove deeply embedded and persistent malware like some rootkits, the described behavior of opening a backdoor is more indicative of a Trojan. A clean install is a drastic measure, typically reserved for severe, unremovable infections, and less intrusive remediation steps should be attempted first.
Go deeper
Related to this question
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.