Courseiva
mediumMultiple ChoiceObjective-mapped

220-1102 Practice Question: That their computer has been acting strangely:…

A user reports that their computer has been acting strangely: files are missing, and the mouse cursor moves on its own, opening programs and typing messages. The technician suspects a remote access Trojan (RAT). What is the most effective immediate action to stop the unauthorized access?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disconnect the Ethernet cable and disable Wi-Fi.

A RAT gives an attacker remote control of the system. The immediate action is to disconnect the computer from the network, which cuts off the attacker's connection. After isolation, the technician can run scans and remove the malware. Continuing to work while connected risks data theft or further damage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Run a full antivirus scan while the user is logged off.

    Why it's wrong here

    Running an antivirus scan on a potentially compromised system before isolating it from the network is a critical mistake. While the user is logged off, a remote attacker could still be actively controlling the system via a Remote Access Trojan (RAT), potentially interfering with the scan, exfiltrating sensitive data, or even deploying additional malware. Network isolation is the essential first step to prevent further damage and ensure the scan's integrity.

  • Disconnect the Ethernet cable and disable Wi-Fi.

    Why this is correct

    Immediately disconnecting the Ethernet cable and disabling Wi-Fi is the most crucial initial step when a system is suspected of being compromised by a remote attacker. This action severs the command and control (C2) communication channel, preventing the attacker from issuing further commands, exfiltrating data, or deploying additional malicious payloads. Network isolation effectively quarantines the infected system, stopping the active threat and allowing for safer forensic analysis and remediation.

  • Change the user's password and log off.

    Why it's wrong here

    Changing the user's password and logging off provides no protection against an active Remote Access Trojan (RAT) or similar malware that has already established persistence on the system. The RAT operates independently of user credentials, often at a system level, allowing the attacker to maintain control even if the user's password is changed. The attacker can simply log back in using their established backdoor, rendering the password change ineffective for remediation.

  • Restore the system to a previous restore point.

    Why it's wrong here

    Restoring the system to a previous restore point might revert some system changes made by malware, but it is not a guaranteed solution for removing all types of sophisticated Remote Access Trojans (RATs). Furthermore, attempting a system restore while the computer is still connected to the network leaves it vulnerable to immediate re-infection or continued attacker activity during the restoration process. Proper network isolation must precede any significant remediation steps like system restoration to ensure effectiveness and prevent recurrence.

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1202

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a routine security audit, a technician discovers that a user's computer has a program that opens a backdoor on port 4444 and allows remote control. The program was installed alongside a free PDF converter the user downloaded last week. Which malware type is this, and what is the most effective removal method?

hard
  • A.Worm; use a network-based firewall to block port 4444.
  • B.Trojan horse; boot into Safe Mode and run a full anti-malware scan.
  • C.Ransomware; pay the ransom to regain control.
  • D.Rootkit; perform a clean installation of Windows.

Why B: The program is a Trojan horse because it disguises itself as a legitimate PDF converter while secretly installing a backdoor. The most effective removal method is to boot into Safe Mode, which loads only essential drivers and services, preventing the Trojan from running, and then perform a full anti-malware scan to detect and remove the malicious files.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.