220-1102 Firmware (UEFI/BIOS) rootkit Practice Question
A security technician has reimaged a user's Windows 10 workstation twice using a standard company image, but the machine continues to exhibit symptoms of a rootkit infection after each reimage. The technician has verified that the removable media used to deploy the image is clean and that the network boot server is not compromised. Which of the following is the MOST likely reason the rootkit persists?
⚠ Common exam trap
Many exam-takers assume reimaging always removes all malware, but the CompTIA A+ exam tests the understanding that firmware-level rootkits persist across OS reinstalls because they reside outside the storage drive's partition table.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The rootkit is embedded in the system's firmware (UEFI/BIOS)
A rootkit that persists after reimaging the operating system is most likely embedded in the system's firmware (UEFI/BIOS). Reimaging only overwrites the storage drive's partitions, but firmware-level rootkits reside in non-volatile memory on the motherboard, which is not touched by standard disk imaging. Since the technician has verified the deployment media and network boot server are clean, the only remaining vector for persistence is the firmware itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The rootkit is embedded in the system's firmware (UEFI/BIOS)
Why this is correct
A UEFI/BIOS rootkit resides in non-volatile firmware memory on the motherboard's SPI flash chip. Because the firmware executes during the pre-boot phase and remains pristine across hard-drive reimages, the malicious code can re-infect the freshly installed Windows 10 from the firmware. Standard drive-wiping or partition reformatting does not touch the firmware; the only reliable remediation is flashing a clean, trusted firmware image or using vendor-specific secure erase procedures.
- ✗
The rootkit is hidden in the user's profile, which was restored from backup
Why it's wrong here
Restoring an old user profile from backup is not part of a standard reimage procedure, which installs a clean OS and typically creates a fresh profile. Unless the technician explicitly restored user data—which the scenario does not state—the profile cannot be the persistence vector. Even if a user-level rootkit came back with a restored profile, it would run in user mode, not beneath the OS like a firmware rootkit, and would be more readily detected.
- ✗
The rootkit is on an external USB drive that is always connected
Why it's wrong here
An external USB drive can carry a bootkit or autorun malware, but the technician likely disconnects peripherals before imaging and testing. For the drive to re-infect the system after every boot, it would need to remain connected and be executed at startup, which is an unusual configuration that a technician would notice. The scenario's persistence despite reimaging points to a source inside the host itself, such as firmware, rather than an easily removable accessory.
- ✗
The rootkit is stored in the Windows registry, which is not erased during reimage
Why it's wrong here
The Windows registry is stored in hive files (e.g., C:\Windows\System32\config) on the system partition, so a full reimage that reformats the drive completely erases the registry. Once the partition is wiped and the OS is reinstalled, no registry data from the prior installation exists to host a rootkit. A firmware rootkit, by contrast, lives outside the drive and is untouched by format operations.
Go deeper
Related to this question
Learn chapter
TPM and Secure Boot
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
Key term
Rootkit
A rootkit is a type of malware that hides its presence and the presence of other malicious software on a computer, often by modifying the operating system itself.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.