Courseiva
hardMultiple Choice

220-1102 Practice Question: A technician is tasked with removing malware from…

A technician is tasked with removing malware from a Windows 10 computer that has a Trojan horse that downloaded additional payloads. The technician has already run a full antivirus scan and removed the Trojan, but the computer still exhibits suspicious network activity. What should the technician do next?

⚠ Common exam trap

CompTIA often tests the misconception that a single antivirus scan is sufficient for complete malware removal, when in fact residual components or stealthy payloads require a second opinion scanner to fully clean the system.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a second opinion malware scanner such as Malwarebytes.

Even after removing the Trojan with a full antivirus scan, the computer may still have residual malware components (e.g., backdoors, keyloggers, or downloaders) that the primary scanner missed. Running a second opinion scanner like Malwarebytes uses a different detection engine and signature database, increasing the chance of identifying and removing these hidden threats. This step is critical because the suspicious network activity indicates an active infection that the first scan failed to fully eradicate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reimage the computer immediately.

    Why it's wrong here

    Reimaging is a last resort; first, attempt further scans to avoid unnecessary downtime.

  • ✓

    Run a second opinion malware scanner such as Malwarebytes.

    Why this is correct

    A second-opinion scanner such as Malwarebytes uses different detection engines and signatures, catching persistent threats, rootkits or dropped payloads the first antivirus missed. Running it addresses the residual suspicious network activity, satisfying the need to remove remaining malware after the initial scan.

  • ✗

    Reset the web browser settings to default.

    Why it's wrong here

    Browser settings govern homepage, extensions and cached data; they have no bearing on a downloaded payload maintaining network connections. Resetting them suits adware or hijacked search pages. The suspicious traffic indicates a separate persistent component that browser configuration cannot remove.

  • ✗

    Disable all startup programs in Task Manager.

    Why it's wrong here

    Disabling startup entries only stops programs launching at logon; it leaves the malicious files on disk and any scheduled task or service intact. It suits trimming legitimate boot overhead. The ongoing network activity points to a persistent payload that must be identified and removed, not merely prevented from starting.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.