hardMultiple Choice
220-1102 Practice Question: A technician is dealing with a zero-day malware…
A technician is dealing with a zero-day malware infection that has evaded all signature-based antivirus scans. The malware is polymorphic, changing its code each time it infects a new system. Which approach is most likely to detect and remove this type of malware?
⚠ Common exam trap
CompTIA often tests the misconception that bootable rescue disks or signature updates can overcome polymorphic or zero-day malware, when in reality only behavior-based or heuristic methods can detect such threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Employ a heuristic-based or behavior-based malware removal tool.
Heuristic and behavior-based detection tools analyze the actions and code patterns of malware rather than relying on static signatures. Since polymorphic malware changes its code with each infection, signature-based detection fails, but behavioral analysis can identify malicious activity such as registry modifications, process injection, or network anomalies. This approach is effective against zero-day threats because it detects anomalies without needing prior knowledge of the specific malware variant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Update the antivirus to the latest signature definitions and run a full scan.
Why it's wrong here
Signature definitions cannot match polymorphic code that rewrites itself on each infection, so a full scan finds nothing. Updating definitions is correct for known, non-mutating threats, which is why it is tempting here despite the malware evading signature detection entirely.
- ✗
Use a bootable antivirus rescue disk to scan the system before the OS loads.
Why it's wrong here
A rescue disk still relies on signature scanning, so it cannot identify polymorphic code that has no stable signature. Offline scanning is correct when malware blocks the running OS from being cleaned, not when detection itself is the obstacle.
- ✓
Employ a heuristic-based or behavior-based malware removal tool.
Why this is correct
Heuristic and behaviour-based tools detect malicious actions and structural traits rather than fixed signatures, so polymorphic code that rewrites itself each infection still exhibits the same runtime behaviour and is caught. Signature scanning fails because no stable byte pattern persists.
- ✗
Reinstall the operating system from a known-good backup.
Why it's wrong here
Reinstalling from backup restores the system but does not detect or remove the malware, and an infected backup reintroduces it. This is correct for unrecoverable corruption or ransomware where eradication is impossible, not for identifying a zero-day infection.
Go deeper
Related to this question
Learn chapter
Malware Types and Removal
Key term
Registry
The Windows Registry is a central hierarchical database that stores configuration settings and options for the operating system, hardware, software, and user preferences.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.