hardMultiple Choice
220-1102 Practice Question: A technician discovers that a Windows 10…
A technician discovers that a Windows 10 workstation has been infected with a fileless malware that resides in memory. Traditional antivirus scans have not detected it. Which approach should the technician use to remove this type of malware?
⚠ Common exam trap
Many exam-takers assume Safe Mode or a signature-based removal tool like MSRT can handle all malware types, but fileless malware specifically evades these by not writing to disk and by running within trusted system processes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Boot from a rescue disk and perform an offline scan.
Fileless malware resides entirely in memory (RAM) and does not write persistent files to disk, so traditional antivirus scans that rely on file signatures cannot detect it. Booting from a rescue disk (e.g., a bootable USB or CD with an offline scanner) loads a clean operating system that bypasses the infected Windows environment, allowing the scanner to inspect memory and terminate the malware without the malware being able to hide or protect itself. This offline approach ensures the malware's process cannot interfere with the scan, making it the correct remediation method.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan in normal mode.
Why it's wrong here
A full antivirus scan in normal mode runs inside the same Windows environment that is already compromised. Fileless malware resides in system memory, registry subkeys, or via PowerShell/WMI scripting, so signature-based scanning of the file system will find no malicious executable to quarantine. Additionally, an active infection can hook API calls or patch scan processes to hide its artifacts from the scanning engine.
- ✗
Use the Windows Malicious Software Removal Tool (MSRT) in Safe Mode.
Why it's wrong here
The Malicious Software Removal Tool is a limited, signature-based utility designed to remove a small subset of prevalent threats; it is not a real-time or behavioral scanner. While Safe Mode stops many startup drivers and scheduled tasks, the Windows kernel itself remains running, and fileless malware can inject into legitimate processes like svchost.exe or hide in registry auto-start keys that MSRT does not deeply inspect. MSRT also cannot detect rootkits or memory-only threats.
- ✓
Boot from a rescue disk and perform an offline scan.
Why this is correct
Booting from a rescue disk (such as Windows Defender Offline or a Linux-based AV live CD) starts from a trusted, read-only environment outside the infected operating system, preventing malware from loading or masking itself. The AV engine can then scan the offline Windows partition, registry hives, and even memory artifacts without interference from active malicious processes. This is the correct approach because fileless malware loses its hiding place when the original OS is not booted.
- ✗
Restore the system from a backup taken before the infection.
Why it's wrong here
Restoring from a backup is not a viable remediation for an active fileless infection unless the backup is from a known-clean point and the original attack vector is closed. If the backup image contains the infection or post-dates it, you simply reinstall the malware; if it is clean, the same vulnerability or credential misuse that introduced the fileless malware remains, allowing immediate re-infection. A restore also does nothing to scrub memory-resident payloads or registry injection points that survive outside the file system.
Go deeper
Related to this question
Learn chapter
Windows Disk Management
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.