mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: That their computer has been acting strangely:…
A user reports that their computer has been acting strangely: files are missing, and the mouse cursor moves on its own, opening programs and typing messages. The technician suspects a remote access Trojan (RAT). What is the most effective immediate action to stop the unauthorized access?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the Ethernet cable and disable Wi-Fi.
A RAT gives an attacker remote control of the system. The immediate action is to disconnect the computer from the network, which cuts off the attacker's connection. After isolation, the technician can run scans and remove the malware. Continuing to work while connected risks data theft or further damage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan while the user is logged off.
Why it's wrong here
Running an antivirus scan on a potentially compromised system before isolating it from the network is a critical mistake. While the user is logged off, a remote attacker could still be actively controlling the system via a Remote Access Trojan (RAT), potentially interfering with the scan, exfiltrating sensitive data, or even deploying additional malware. Network isolation is the essential first step to prevent further damage and ensure the scan's integrity.
- ✓
Disconnect the Ethernet cable and disable Wi-Fi.
Why this is correct
Immediately disconnecting the Ethernet cable and disabling Wi-Fi is the most crucial initial step when a system is suspected of being compromised by a remote attacker. This action severs the command and control (C2) communication channel, preventing the attacker from issuing further commands, exfiltrating data, or deploying additional malicious payloads. Network isolation effectively quarantines the infected system, stopping the active threat and allowing for safer forensic analysis and remediation.
- ✗
Change the user's password and log off.
Why it's wrong here
Changing the user's password and logging off provides no protection against an active Remote Access Trojan (RAT) or similar malware that has already established persistence on the system. The RAT operates independently of user credentials, often at a system level, allowing the attacker to maintain control even if the user's password is changed. The attacker can simply log back in using their established backdoor, rendering the password change ineffective for remediation.
- ✗
Restore the system to a previous restore point.
Why it's wrong here
Restoring the system to a previous restore point might revert some system changes made by malware, but it is not a guaranteed solution for removing all types of sophisticated Remote Access Trojans (RATs). Furthermore, attempting a system restore while the computer is still connected to the network leaves it vulnerable to immediate re-infection or continued attacker activity during the restoration process. Proper network isolation must precede any significant remediation steps like system restoration to ensure effectiveness and prevent recurrence.
Go deeper
Related to this question
Learn chapter
Malware Types and Removal
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Trojan
A Trojan is a type of malware that disguises itself as a legitimate file or program to trick users into installing it, then performs harmful actions without the user's knowledge.
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1202
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a routine security audit, a technician discovers that a user's computer has a program that opens a backdoor on port 4444 and allows remote control. The program was installed alongside a free PDF converter the user downloaded last week. Which malware type is this, and what is the most effective removal method?
hard- A.Worm; use a network-based firewall to block port 4444.
- ✓ B.Trojan horse; boot into Safe Mode and run a full anti-malware scan.
- C.Ransomware; pay the ransom to regain control.
- D.Rootkit; perform a clean installation of Windows.
Why B: The program is a Trojan horse because it disguises itself as a legitimate PDF converter while secretly installing a backdoor. The most effective removal method is to boot into Safe Mode, which loads only essential drivers and services, preventing the Trojan from running, and then perform a full anti-malware scan to detect and remove the malicious files.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.