220-1102 Security Practice Question
A security auditor finds that a user's workstation has a scheduled task that runs a PowerShell script every hour. The script connects to an external IP address and downloads a file. The user claims no knowledge of the task. Which of the following is the most likely cause?
⚠ Common exam trap
Watch out — candidates often assume any scheduled task is legitimate (e.g., from Windows Update or IT maintenance), failing to recognize that unauthorized scheduled tasks with external IP connections and PowerShell scripts are a hallmark of malware persistence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The workstation is infected with malware that persists via scheduled tasks
The scheduled task running a PowerShell script that connects to an external IP address to download a file is a classic indicator of malware persistence. Malware often uses scheduled tasks to re-infect or maintain a foothold after reboot, and the user's lack of knowledge strongly suggests unauthorized activity. This aligns with common post-exploitation techniques where attackers use PowerShell for fileless or script-based payloads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The workstation is infected with malware that persists via scheduled tasks
Why this is correct
Malware commonly establishes persistence by creating scheduled tasks that trigger on user logon or at system startup, using high-privilege contexts like SYSTEM to evade user interaction. In this case, the task's connection to an external IP for file downloads aligns with command-and-control behavior, and the user's denial of installing anything further supports a malicious origin. Moreover, attackers often name tasks to mimic legitimate Windows processes, making them difficult to distinguish from normal scheduled operations without inspecting the task's actions and triggers.
- ✗
The user installed a legitimate application that creates scheduled tasks
Why it's wrong here
Legitimate installed applications, such as update checkers or backup utilities, do create scheduled tasks, but those tasks are typically signed, have recognizable publisher names, and target the software's own update servers or well-known domains. The suspect task instead connects to an arbitrary external IP to download files, which is not a pattern seen in routine application maintenance. Additionally, the user explicitly denies installing any new software, weakening the case for an innocent, authorized application-driven task.
- ✗
A remote administrator configured the task for maintenance
Why it's wrong here
A remote administrator's maintenance tasks are usually deployed through centralized management tools like Group Policy or Microsoft Endpoint Configuration Manager, which maintain audit logs and approval records for every scheduled task. They also run against managed endpoints with known update sources, not arbitrary external IPs, and they don't typically download unnamed files directly to the workstation. Since the auditor found no documentation or change-control record matching this task, the remote-maintenance hypothesis is unsupported.
- ✗
The task was created by Windows Update
Why it's wrong here
Windows Update creates scheduled tasks as part of its own servicing stack, but those tasks only invoke Microsoft-signed binaries and communicate with Windows Update servers via HTTPS to well-known Microsoft domains. They would never connect to an external IP address outside Microsoft's range to download arbitrary files. Furthermore, Windows Update tasks are explicitly named (for example, a GUID-based task under the Microsoft\Windows\UpdateOrchestrator folder) and would not be denied by the user, so this explanation conflicts with both the observed behavior and the user's statement.
Go deeper
Related to this question
Learn chapter
Malware Classification: Virus, Worm, Ransomware, Rootkit
Key term
Power-on Self-test
The Power-on Self-test (POST) is a diagnostic process a computer runs immediately when you turn it on to check that essential hardware components are working correctly before loading the operating system.
Key term
POST
Power-On Self-Test (POST) is a diagnostic process that a computer runs when it first powers on to check that essential hardware components are working correctly before loading the operating system.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security auditor discovers that a user's workstation has a scheduled task that runs a PowerShell script every hour connecting to an external IP and downloading a file. The user denies knowledge. Which is the most likely cause?
hard- A.User accidentally created a scheduled task
- ✓ B.Malware infection
- C.Windows Update failure
- D.Incorrect Group Policy
Why B: The scheduled task running a PowerShell script that connects to an external IP and downloads a file every hour is a classic indicator of a backdoor or command-and-control (C2) behavior. Malware often persists by creating scheduled tasks to re-infect or update itself, and the user's denial of knowledge strongly suggests the task was placed without their consent. This aligns with a malware infection, as legitimate users do not typically create such tasks.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.