hardMultiple ChoiceObjective-mapped
220-1102 Practice Question: A security incident is reported: an employee's…
A security incident is reported: an employee's company-issued Android phone is displaying persistent pop-up ads, even when no browser is open. The employee admits to side-loading a game from an unknown website. What is the most likely cause and best immediate action?
⚠ Common exam trap
CompTIA often tests the distinction between adware and a general virus, and the trap here is that candidates may jump to a factory reset (Option A) without considering the less destructive safe-mode uninstall, or they may incorrectly attribute the pop-ups to the browser (Option C) when the behavior occurs system-wide.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The side-loaded app is adware; boot into safe mode and uninstall it.
The persistent pop-up ads, even without a browser open, indicate adware behavior typical of malicious apps. Since the employee side-loaded a game from an unknown website, the most likely cause is that the side-loaded app contains adware. Booting into safe mode (which disables third-party apps) and uninstalling the suspicious app is the best immediate action because it removes the adware without data loss, unlike a factory reset.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The phone has a virus; perform a factory reset immediately.
Why it's wrong here
A factory reset is a destructive action that erases all user data, settings, and installed applications from the device. While effective against many forms of malware, it should be considered a last resort due to the significant data loss and inconvenience it causes. Less destructive methods, such as booting into safe mode to isolate and remove the offending application, should always be attempted first to preserve user data and minimize downtime.
- ✓
The side-loaded app is adware; boot into safe mode and uninstall it.
Why this is correct
Side-loaded applications, especially from untrusted sources, are a common vector for adware and other potentially unwanted programs on Android devices. Booting an Android device into safe mode temporarily disables all third-party applications, preventing the adware from running and interfering with its removal. This allows the user to safely navigate to the device's application settings and uninstall the malicious side-loaded app without it actively resisting or re-installing itself.
- ✗
The browser is infected; clear the browser cache and data.
Why it's wrong here
Clearing browser cache and data is an appropriate troubleshooting step for browser-specific issues like persistent pop-ups or slow performance within the browser itself. However, if the reported security incident involves advertisements appearing outside of the browser application or system-wide, it indicates a deeper, system-level infection, likely from a malicious app. In such cases, addressing only the browser will not resolve the root cause of the adware.
- ✗
The phone's firmware is compromised; reflash the stock ROM.
Why it's wrong here
Reflashing the stock ROM involves completely reinstalling the operating system firmware, which is a highly invasive and potentially risky procedure. While it can resolve deep-seated system corruption or rootkits, it is an extreme measure for typical adware infections caused by side-loaded applications. Adware usually resides in the user-installed application layer, making it removable through standard uninstallation processes, especially when performed in safe mode, without resorting to firmware manipulation.
Go deeper
Related to this question
Learn chapter
Virtualization and Client-Side
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.