Courseiva
Software Troubleshooting →mediumMultiple Choice

220-1102 Practice Question: Runs outside the main Windows operating system.

A technician suspects that a Windows 10 computer is infected with malware that prevents the user from opening Task Manager and Command Prompt. Which tool should the technician use to run a virus scan from outside the operating system?

⚠ Common exam trap

220-1102 often tests the difference between tools that run within Windows (Safe Mode, System Restore) and those that run outside (Windows Defender Offline), and candidates may incorrectly choose Safe Mode thinking it isolates malware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Defender Offline

Windows Defender Offline is designed to run a virus scan from outside the operating system, booting from a trusted environment to remove malware that may be deeply embedded or resistant to removal while Windows is running. It is the appropriate tool when malware blocks access to Task Manager and Command Prompt, as it bypasses the infected OS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Windows Defender Offline

    Why this is correct

    Windows Defender Offline is designed to boot from a trusted pre-installation environment before the operating system loads, meaning malware that hooks into the Windows kernel or registry is not active and cannot interfere with the scan. It performs a deep scan of the file system and boot sectors, making it effective for removing rootkits, bootkits, and other stubborn malware that resist detection in a running Windows session. Because it runs outside the compromised OS, it can delete files that would otherwise be locked or hidden by malicious processes.

  • ✗

    System Restore

    Why it's wrong here

    System Restore rolls back system files, registry keys, and installed programs to a previous restore point, but it does not perform any virus or malware scanning. Malware often resides in user profile folders, startup entries, or peripheral files that are not fully reverted by a system restore, and any active threat can simply re-infect the system immediately after the restoration completes. Thus, while it can undo system changes, it is neither designed nor appropriate for malware removal.

  • ✗

    Safe Mode

    Why it's wrong here

    Safe Mode loads Windows with a minimal set of drivers and services to aid troubleshooting, but it does not disable the local file system or prevent malware that runs as a system service or startup program from loading. Many malicious programs are specifically written to persist in Safe Mode or to tamper with security tools, so the infection may remain active and prevent you from running a successful scan or removal. It is a diagnostic environment for isolating driver and boot issues, not a comprehensive disinfection method.

  • ✗

    Last Known Good Configuration

    Why it's wrong here

    Last Known Good Configuration only reverts to the most recent control set that produced a successful boot, which is a registry setting used to work around improper driver or service configurations. It does not scan for malware and does not remove or quarantine any malicious files. Moreover, if the system booted successfully after the malware installed, the last known good configuration will still include the infection, making this option ineffective for addressing a malware problem.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A technician suspects that a Windows 10 computer is infected with malware. The technician wants to use built-in and trusted third-party tools to clean the system. Which two of the following actions should the technician take? (Select TWO).

medium
  • ✓ A.Run a full scan with Windows Defender
  • B.Run sfc /scannow
  • ✓ C.Run Malwarebytes Anti-Malware
  • D.Run Disk Cleanup

Why A: Windows Defender (now Microsoft Defender Antivirus) is a built-in antimalware solution in Windows 10 that can perform full system scans to detect and remove malware. Running a full scan leverages a trusted, integrated tool without additional cost or installation. Malwarebytes Anti-Malware is a respected third-party antimalware tool that can detect and remove threats that might be missed by built-in solutions, providing an extra layer of cleaning. Together, these are appropriate actions for cleaning an infected system. sfc /scannow is for verifying system files, and Disk Cleanup is for freeing disk space—neither is designed for malware removal.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.