220-1102 Practice Question: Runs outside the main Windows operating system.
A technician suspects that a Windows 10 computer is infected with malware that prevents the user from opening Task Manager and Command Prompt. Which tool should the technician use to run a virus scan from outside the operating system?
⚠ Common exam trap
220-1102 often tests the difference between tools that run within Windows (Safe Mode, System Restore) and those that run outside (Windows Defender Offline), and candidates may incorrectly choose Safe Mode thinking it isolates malware.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Defender Offline
Windows Defender Offline is designed to run a virus scan from outside the operating system, booting from a trusted environment to remove malware that may be deeply embedded or resistant to removal while Windows is running. It is the appropriate tool when malware blocks access to Task Manager and Command Prompt, as it bypasses the infected OS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Windows Defender Offline
Why this is correct
Windows Defender Offline is designed to boot from a trusted pre-installation environment before the operating system loads, meaning malware that hooks into the Windows kernel or registry is not active and cannot interfere with the scan. It performs a deep scan of the file system and boot sectors, making it effective for removing rootkits, bootkits, and other stubborn malware that resist detection in a running Windows session. Because it runs outside the compromised OS, it can delete files that would otherwise be locked or hidden by malicious processes.
- ✗
System Restore
Why it's wrong here
System Restore rolls back system files, registry keys, and installed programs to a previous restore point, but it does not perform any virus or malware scanning. Malware often resides in user profile folders, startup entries, or peripheral files that are not fully reverted by a system restore, and any active threat can simply re-infect the system immediately after the restoration completes. Thus, while it can undo system changes, it is neither designed nor appropriate for malware removal.
- ✗
Safe Mode
Why it's wrong here
Safe Mode loads Windows with a minimal set of drivers and services to aid troubleshooting, but it does not disable the local file system or prevent malware that runs as a system service or startup program from loading. Many malicious programs are specifically written to persist in Safe Mode or to tamper with security tools, so the infection may remain active and prevent you from running a successful scan or removal. It is a diagnostic environment for isolating driver and boot issues, not a comprehensive disinfection method.
- ✗
Last Known Good Configuration
Why it's wrong here
Last Known Good Configuration only reverts to the most recent control set that produced a successful boot, which is a registry setting used to work around improper driver or service configurations. It does not scan for malware and does not remove or quarantine any malicious files. Moreover, if the system booted successfully after the malware installed, the last known good configuration will still include the infection, making this option ineffective for addressing a malware problem.
Go deeper
Related to this question
Learn chapter
Windows User Accounts and Groups
Key term
Task Manager
Task Manager is a built-in Windows utility that shows running programs, processes, and system performance, allowing users to monitor and manage computer activity.
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A technician suspects that a Windows 10 computer is infected with malware. The technician wants to use built-in and trusted third-party tools to clean the system. Which two of the following actions should the technician take? (Select TWO).
medium- ✓ A.Run a full scan with Windows Defender
- B.Run sfc /scannow
- ✓ C.Run Malwarebytes Anti-Malware
- D.Run Disk Cleanup
Why A: Windows Defender (now Microsoft Defender Antivirus) is a built-in antimalware solution in Windows 10 that can perform full system scans to detect and remove malware. Running a full scan leverages a trusted, integrated tool without additional cost or installation. Malwarebytes Anti-Malware is a respected third-party antimalware tool that can detect and remove threats that might be missed by built-in solutions, providing an extra layer of cleaning. Together, these are appropriate actions for cleaning an infected system. sfc /scannow is for verifying system files, and Disk Cleanup is for freeing disk space—neither is designed for malware removal.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.