Question 623 of 1,000
mediummultiple choiceObjective-mapped

220-1102 Practice Question: A technician suspects that a malware infection on…

This 220-1102 practice question tests your understanding of a technician suspects that a malware infection on…. The scenario asks you to isolate a root cause — eliminate options that address a different problem before choosing. A key principle to apply: resource Monitor displays real-time network connections per process.. Once you have made your selection, read the full explanation to reinforce the concept and understand why each distractor is designed to mislead on exam day.

A technician suspects that a malware infection on a Windows 10 workstation is communicating with a remote command-and-control server. The technician needs to identify which process is making outbound connections. Which built-in Windows tool is best suited for this task?

Question 1mediummultiple choice
Full question →

A technician suspects that a malware infection on a Windows 10 workstation is communicating with a remote command-and-control server. The technician needs to identify which process is making outbound connections. Which built-in Windows tool is best suited for this task?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Task Manager

Task Manager displays network usage per process but does not show specific remote addresses or connection states, which are necessary to identify C2 communication.

B

Best answer

Resource Monitor

Resource Monitor (accessible via Task Manager or perfmon /res) includes a Network tab that lists processes with TCP connections, remote IP addresses, and ports, making it ideal for identifying suspicious outbound traffic.

C

Distractor review

Performance Monitor

Performance Monitor is used for logging performance counters over time, not for real-time per-process network connection details.

D

Distractor review

Event Viewer

Event Viewer logs events such as security or system errors, but it does not provide a live view of current network connections per process.

Answer analysis

Why the other options are wrong

Understanding why incorrect options are tempting is as important as knowing the correct answer.

  • Task Manager

    Task Manager displays network usage per process but does not show specific remote addresses or connection states, which are necessary to identify C2 communication.

  • Performance Monitor

    Performance Monitor is used for logging performance counters over time, not for real-time per-process network connection details.

  • Event Viewer

    Event Viewer logs events such as security or system errors, but it does not provide a live view of current network connections per process.

Common exam trap

Common exam trap: answer the scenario, not the keyword

Candidates might be tempted by Task Manager because it shows network usage, but it lacks the critical detail of remote IP addresses and ports.

Technical deep dive

How to think about this question

Resource Monitor is the optimal built-in Windows tool for this scenario because its Network tab provides a granular, real-time view of active network connections, broken down by process. When a technician suspects a malware infection is communicating with a command-and-control (C2) server, they need to see not just that a process is using the network, but specifically which remote IP address and port it's connecting to. Resource Monitor excels here by listing each process with an active TCP connection, displaying the local and remote addresses, the port numbers, and the connection state. This level of detail allows the technician to quickly identify unusual outbound connections to unknown or suspicious remote hosts, which is a hallmark of C2 communication. For instance, if 'svchost.exe' is making an unexpected outbound connection to a public IP address on an unusual port, Resource Monitor would immediately highlight this, enabling further investigation. While Task Manager shows network activity per process, it lacks the critical detail of remote IP addresses and ports, making it insufficient for pinpointing C2 traffic. It might show high network usage for a process, but without knowing the destination, it's difficult to determine if it's malicious. Performance Monitor, on the other hand, is designed for collecting and analyzing system performance data over time using counters, not for displaying live, per-process connection details. It can track network interface statistics but won't attribute specific connections to individual processes in the way Resource Monitor does. Event Viewer logs system events and security audits, which might contain clues about a malware infection after the fact (e.g., failed login attempts, service installations), but it does not offer a real-time, active view of network connections, making it unsuitable for immediate identification of outbound C2 communication.

KKey Concepts to Remember

  • Resource Monitor displays real-time network connections per process.
  • It shows local and remote IP addresses and port numbers for TCP connections.
  • Resource Monitor can be accessed via Task Manager or by running 'perfmon /res'.
  • It helps identify suspicious outbound traffic to unknown remote hosts.

TExam Day Tips

  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Key takeaway

Resource Monitor displays real-time network connections per process.

Related practice questions

Related 220-1102 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

Question 1

A change advisory board (CAB) approved a standard change to update antivirus definitions on all servers. The technician completes the update on a file server and verifies the server is functioning normally. According to change management best practices, what documentation should the technician complete?

Question 2

A company's change management policy requires all server changes to be approved by the Change Advisory Board (CAB). A technician discovers that a critical database server's operating system needs a security patch to comply with a new regulatory requirement that takes effect in one week. The patch has a known risk of causing service downtime. The next scheduled CAB meeting is in two weeks. What should the technician do FIRST?

Question 3

A company is implementing a bring-your-own-device (BYOD) policy and needs to ensure that corporate data on employee mobile devices is protected. Which of the following is the MOST important technical control to implement?

Question 4

A company requires employees to present both a smart card and a PIN to log into their workstations. Which authentication principle is being implemented?

Question 5

A company requires all Windows 10 workstations to be able to join an Active Directory domain. Which edition of Windows 10 must be installed on these workstations?

Question 6

A company wants to allow employees to securely access internal resources from home via the internet. Which method provides the highest level of security for remote desktop connections?

Practice this exam

Start a free 220-1102 practice session

Short sessions build daily habit. Longer sessions build exam-day stamina. Try a timed session to simulate real conditions.

FAQ

Questions learners often ask

What does this 220-1102 question test?

Resource Monitor displays real-time network connections per process.

What is the correct answer to this question?

The correct answer is: Resource Monitor — Resource Monitor provides detailed real-time information about network activity per process, including TCP connections, send/receive rates, and remote addresses. While Task Manager shows overall network utilization per process, Resource Monitor offers more granular data for troubleshooting suspicious outbound connections.

What should I do if I get this 220-1102 question wrong?

Review resource Monitor displays real-time network connections per process., then practise related 220-1102 questions on the same topic to reinforce the concept.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Keep practising

More 220-1102 practice questions

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.