mediumMultiple Choice
220-1102 Practice Question: A user calls the help desk because they received…
A user calls the help desk because they received a pop-up on their screen claiming their computer is infected with a virus and to call a toll-free number for immediate support. The user did not call the number. What should the technician advise the user to do?
⚠ Common exam trap
Test-takers frequently confuse a tech support scam pop-up with a legitimate security warning and think calling the number or rebooting is the correct response, but CompTIA emphasizes that the proper procedure is to never engage with the scam and to run a security scan to ensure the system is clean.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Close the pop-up and run a full antivirus scan.
The pop-up is a classic tech support scam, a form of social engineering. The user should close the pop-up (e.g., using Task Manager or Alt+F4) and immediately run a full antivirus scan to detect and remove any potential malware that may have triggered the pop-up or been downloaded in the background. This ensures the system is cleaned and prevents further compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Call the number to see if it's legitimate.
Why it's wrong here
Calling connects the user to fraudsters who will request remote access or payment; the pop-up is unsolicited, so its toll-free number carries no legitimacy to verify. It tempts because verifying a warning sounds cautious, but phoning is appropriate only for a known vendor's published support line.
- ✗
Ignore the pop-up and continue working.
Why it's wrong here
Ignoring the pop-up leaves the browser session, and any malicious script or downloaded payload, active; the alert is a tech-support scam that must be closed and the browser cleared. It tempts because the message is fake, but ignoring suits genuine nuisance ads, not infection warnings demanding a phone call.
- ✓
Close the pop-up and run a full antivirus scan.
Why this is correct
The pop-up is a tech-support scam using scareware, not a genuine infection alert, so the user must not call the number. Closing the browser window and running a full antivirus scan removes any dropped payload and confirms the machine's state.
- ✗
Reboot the computer immediately.
Why it's wrong here
Rebooting does not remove the scam page, which typically relaunches from the browser's restored session, and it destroys evidence such as the URL before remediation. It tempts as a universal first fix, but restarting suits frozen applications or driver faults, not browser-based social-engineering pop-ups.
Go deeper
Related to this question
Learn chapter
Windows User Accounts and Groups
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Task Manager
Task Manager is a built-in Windows utility that shows running programs, processes, and system performance, allowing users to monitor and manage computer activity.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.