easyMultiple ChoiceObjective-mapped
220-1102 Practice Question: That their computer is infected with a virus and…
A user reports that their computer is infected with a virus and they have been trying to remove it using a free online scanner, but the problem persists. The technician suspects the malware may have disabled the antivirus software. Which safe mode should the technician use to run a full system scan?
⚠ Common exam trap
CompTIA often tests the distinction between Safe Mode and Safe Mode with Networking, where candidates mistakenly choose Safe Mode without realizing that antivirus software often requires network access to download updated signatures for effective malware removal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Safe Mode with Networking
Safe Mode with Networking (C) is correct because it loads only essential drivers and services, including network components, which allows the technician to run a full system scan while the malware is likely inactive. Since the malware may have disabled the antivirus software in normal mode, booting into Safe Mode with Networking ensures the antivirus can run and still access the internet for signature updates or cloud-based scanning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Safe Mode
Why it's wrong here
Safe Mode loads Windows with a minimal set of drivers and services, effectively disabling most third-party applications, including many malware components. However, this specific mode intentionally disables network connectivity. Without internet access, a technician cannot download crucial updated antivirus definitions, new malware removal tools, or research specific threats, making comprehensive malware eradication extremely difficult and often impossible.
- ✗
Safe Mode with Command Prompt
Why it's wrong here
Safe Mode with Command Prompt is an even more restrictive diagnostic environment, loading only essential system services and presenting a command-line interface instead of the graphical desktop. While powerful for advanced system repairs or file manipulation via command-line tools, it completely lacks network access and a graphical user interface. Most modern antivirus and anti-malware applications require a GUI for effective scanning and remediation, rendering this mode unsuitable for typical malware removal procedures.
- ✓
Safe Mode with Networking
Why this is correct
Safe Mode with Networking is the optimal choice for malware removal because it loads Windows with a minimal set of drivers and services, effectively preventing most malware from loading and executing. Crucially, this mode enables network connectivity, allowing the technician to download the latest antivirus definition updates, specialized malware removal tools, and access online resources for threat analysis. This combination ensures a clean, isolated environment for effective remediation while providing necessary external resources.
- ✗
Last Known Good Configuration
Why it's wrong here
Last Known Good Configuration (LKGC) is a recovery option designed to revert system settings and drivers to the state of the last successful boot. While useful for resolving boot issues caused by recent driver or software installations, it does not address malware infections. LKGC only restores configuration data, not system files or the registry entries where malware often embeds itself, meaning the malicious software would likely persist and reactivate upon a normal boot.
Go deeper
Related to this question
Learn chapter
Windows Networking and File Sharing
Key term
Virus
A virus is a malicious software program that attaches itself to legitimate files or programs and spreads to other systems, often causing damage or stealing information.
Key term
Safe Mode
Safe Mode is a diagnostic startup mode in operating systems that loads only essential drivers and services, allowing users to troubleshoot and fix problems caused by non-critical software or hardware.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.