mediumMultiple Choice
220-1102 Practice Question: A user calls the help desk saying that every time…
A user calls the help desk saying that every time they click a link in an email, their browser opens a page that says 'Your computer is infected! Call this number.' They are unable to close the page normally. What type of attack is this, and what is the first step you should take?
⚠ Common exam trap
220-1202 often tests whether candidates can distinguish between similar-sounding attack types (phishing, browser hijacker, tech support scam, drive-by download) and identify the correct first response, so the trap is choosing a plausible-sounding attack type or a response that is not the immediate first step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Tech support scam; force close the browser using Task Manager, then run a security scan
The symptoms — a browser page claiming the computer is infected and demanding a phone call, plus inability to close the page normally — are classic indicators of a tech support scam, often delivered via malvertising or malicious ads. The immediate first step is to force-close the browser (e.g., via Task Manager) to stop the script, then run a security scan to check for any payload or persistence. Changing passwords or disconnecting the network may be appropriate later, but the question asks for the first step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing attack; immediately change the user's email password
Why it's wrong here
This scenario describes a persistent, unclosable fake alert displayed within a browser, which is characteristic of scareware or a tech support scam, not a typical phishing attack. Phishing primarily relies on social engineering via deceptive emails or fraudulent websites to trick users into voluntarily divulging credentials directly. While a password change might be necessary if credentials were actually compromised, it is premature and misdirected as the immediate response to a persistent browser alert that has not yet demonstrated credential theft.
- ✗
Browser hijacker; run a full antivirus scan immediately
Why it's wrong here
While a browser hijacker could be a contributing factor to the appearance of such an alert, the immediate and most critical step when encountering a persistent, unclosable fake alert is to terminate the browser process. Running a full antivirus scan, though an essential subsequent step for remediation and detection of underlying malware, cannot be initiated effectively while the malicious alert is actively preventing user interaction or consuming system resources. Containment of the active threat must precede a full system scan.
- ✓
Tech support scam; force close the browser using Task Manager, then run a security scan
Why this is correct
This option accurately identifies the threat as a tech support scam, which typically involves displaying a persistent, unclosable browser alert designed to panic the user into calling a fraudulent "support" number. The immediate and effective first step is to force close the browser using Task Manager (Ctrl+Shift+Esc on Windows) to stop the active scam page from locking the browser. Subsequently, running a comprehensive security scan is crucial to detect and remove any underlying malware or adware that might have facilitated the scam page's appearance.
- ✗
Drive-by download; disconnect the computer from the network
Why it's wrong here
A drive-by download refers to malware being installed on a user's computer without their knowledge or explicit consent, often by simply visiting a compromised website. This process is typically silent and background-oriented, contrasting sharply with the visible, persistent fake alert described in the scenario. While disconnecting from the network is a valid containment step for some malware infections, it is not the primary immediate response to a visible, interactive browser-based scam that requires process termination to regain control.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Task Manager
Task Manager is a built-in Windows utility that shows running programs, processes, and system performance, allowing users to monitor and manage computer activity.
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.