Courseiva
mediumMultiple Choice

220-1202 Practice Question: During a security audit, you discover that a…

During a security audit, you discover that a user's workstation has an unauthorized application running. You need to terminate the process immediately from the command line. The process name is 'malware.exe'. Which command should you use?

⚠ Common exam trap

Many candidates confuse `tasklist` (a listing tool) with `taskkill` (a termination tool), or assume `net stop` can stop any running program, when in fact it only applies to Windows services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

taskkill /IM malware.exe /F

The `taskkill` command with the `/IM` (image name) and `/F` (force) flags is the standard Windows CLI method to forcibly terminate a process by its executable name. This directly stops 'malware.exe' without requiring the process ID, making it the appropriate tool for immediate termination during a security incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    tasklist /FI "IMAGENAME eq malware.exe"

    Why it's wrong here

    'tasklist' only enumerates running processes and their details; it cannot terminate anything. The scenario demands immediate termination, which requires 'taskkill /IM malware.exe'. Listing is tempting because it confirms the process exists first, and it would be the right choice when auditing what is running rather than stopping it.

  • ✓

    taskkill /IM malware.exe /F

    Why this is correct

    `taskkill /IM malware.exe /F` targets the process by image name and forces termination, satisfying the requirement to end the unauthorised application immediately from the command line. The `/IM` switch matches `malware.exe` regardless of its process identifier, while `/F` overrides any refusal to close, ensuring the process stops without interactive prompts.

  • ✗

    net stop malware

    Why it's wrong here

    'net stop' targets Windows services registered with the Service Control Manager, not arbitrary executables; 'malware.exe' is a process, so the command fails. It is tempting because both stop running software, and it would be correct for halting a named service such as 'net stop spooler'.

  • ✗

    shutdown /r /t 0

    Why it's wrong here

    'shutdown /r /t 0' reboots the machine, which restarts services and may relaunch the unauthorised application while disrupting the user. It is tempting as a blunt way to clear a rogue process, and would be correct when the goal is a planned restart, not targeted process termination.

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.