hardMultiple ChoiceObjective-mapped
220-1102 Practice Question: A security incident has occurred: a user's Mac…
A security incident has occurred: a user's Mac running macOS Ventura was infected with malware that modified system files. The technician needs to boot the Mac into a mode that loads only essential Apple-signed kernel extensions and prevents third-party software from loading, in order to safely remove the malware. Which startup mode should they use?
⚠ Common exam trap
The 220-1202 exam often tests the distinction between startup modes that change the boot environment (Safe Mode) versus those that only alter the user interface or provide diagnostic output (Verbose, Single-user), leading candidates to mistakenly choose Single-user mode for malware removal when it does not restrict third-party kernel extensions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safe Mode (Shift key during startup).
Safe Mode (Shift key during startup) is correct because it forces macOS to load only essential kernel extensions that are signed by Apple, disables all third-party startup items and login items, and runs a directory integrity check. This minimal environment prevents the malware from loading its own kernel extensions or other malicious code, allowing the technician to safely remove the infected files without interference.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Single-user mode (Command + S).
Why it's wrong here
While Single-user mode provides a root shell for command-line diagnostics, it primarily bypasses the graphical user interface and does not actively disable or prevent the loading of all third-party kernel extensions or startup items that might be malicious. Furthermore, its availability is limited to Intel-based Macs, making it an unsuitable general solution for a security incident on potentially newer Apple Silicon hardware.
- ✗
Verbose mode (Command + V).
Why it's wrong here
Verbose mode simply alters the boot process to display system messages and kernel output on the screen instead of the Apple logo. It offers no protective measures against malware, as all normal system processes, drivers, and startup items, including potentially malicious ones, are still loaded as usual. Its primary utility is for diagnosing boot issues by observing the sequence of events, not for security isolation.
- ✓
Safe Mode (Shift key during startup).
Why this is correct
Safe Mode is specifically designed to isolate system issues by loading only essential macOS components and disabling all non-Apple kernel extensions, startup items, and login items. This creates a clean, minimal environment where malware, which often relies on these non-essential components, is prevented from loading or executing, making it an ideal state for diagnosis and removal during a security incident. Additionally, it performs a basic check of the startup disk for errors.
- ✗
Target Disk Mode (T key).
Why it's wrong here
Target Disk Mode transforms the affected Mac into an external hard drive accessible by another computer via Thunderbolt or FireWire. While this allows for data recovery or scanning the disk from a known-good system, it does not prevent the malware from existing on the drive itself. The compromised Mac's operating system is not booted in this mode, but the malicious files remain on the storage, potentially transferable if not handled carefully by the connecting machine.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
macOS and Linux Basics for A+
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Safe Mode
Safe Mode is a diagnostic startup mode in operating systems that loads only essential drivers and services, allowing users to troubleshoot and fix problems caused by non-critical software or hardware.
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.