Courseiva
mediumMultiple ChoiceObjective-mapped

220-1102 Practice Question: A technician is troubleshooting a Windows 10…

A technician is troubleshooting a Windows 10 workstation that displays a fake security alert claiming the system is infected and prompting the user to call a toll-free number. The user cannot close the alert window or open Task Manager. Which type of malware is causing this behavior, and what is the best removal approach?

⚠ Common exam trap

The 220-1202 exam often tests the distinction between ransomware (which encrypts data) and tech support scams (which only display fake alerts), leading candidates to confuse the visible popup with actual file-encrypting malware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

It is a tech support scam; boot into Safe Mode with Networking and run an anti-malware scan.

The fake security alert that cannot be closed and blocks Task Manager is a classic tech support scam, not actual malware that encrypts files or hides deep in the system. Booting into Safe Mode with Networking loads only essential drivers and services, bypassing the scam's persistence mechanism, and allows an anti-malware scan to remove the malicious files and registry entries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • It is a rootkit; use a rootkit removal tool from within Windows.

    Why it's wrong here

    This scenario describes a browser-based alert or scareware, not a rootkit. Rootkits are stealthy malware designed to hide their presence and provide persistent, privileged access to an attacker, often operating at the kernel level. Attempting to remove a sophisticated rootkit from within a compromised Windows environment is generally ineffective, as the rootkit itself can subvert security tools and hide its components.

  • It is ransomware; pay the fee to remove the alert.

    Why it's wrong here

    This is not ransomware because the user's files are not encrypted, nor is the system locked down by the malware itself. Ransomware specifically encrypts data or locks the operating system, demanding payment for decryption keys or system access restoration. Paying the fee in a tech support scam merely validates the scammer's business model and provides no guarantee of resolution, often leading to further demands or installation of more malicious software.

  • It is a tech support scam; boot into Safe Mode with Networking and run an anti-malware scan.

    Why this is correct

    This is the correct approach for a tech support scam, which typically involves browser-based pop-ups or installed scareware designed to trick users into calling fake support numbers. Booting into Safe Mode with Networking loads only essential drivers and services, preventing the scam's malicious processes from fully executing and allowing network access for anti-malware updates. Running a comprehensive anti-malware scan can then effectively identify and remove the associated files, browser extensions, and registry entries.

  • It is a worm; disconnect the network and reinstall the operating system.

    Why it's wrong here

    This scenario does not describe a worm, which is a self-replicating malware designed to spread autonomously across networks to infect other systems without user intervention. A tech support scam is typically confined to a single workstation, often initiated by user interaction with a malicious link or pop-up. Disconnecting the network and immediately reinstalling the operating system is an overly drastic and unnecessary measure for a tech support scam, which can usually be resolved through targeted malware removal.

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.