Courseiva
mediumMultiple ChoiceObjective-mapped

220-1102 Practice Question: That their computer is running slowly and they…

A user reports that their computer is running slowly and they suspect a virus. After scanning, the technician finds malware that has encrypted several files. The technician decides to wipe the drive and reinstall the OS. What should be done to ensure the malware is completely removed before data destruction?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a secure erase utility that overwrites the entire drive including the boot sector.

Some malware can persist in the boot sector or firmware. A full wipe of the entire drive (including the boot sector) using a secure erase or low-level format ensures no malware remnants remain. A simple format may leave boot-sector malware intact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Run a quick format and then reinstall the OS.

    Why it's wrong here

    A quick format primarily removes the file system journaling and directory entries, making the space available for new data without physically overwriting all sectors. This method leaves the boot sector and other low-level disk areas untouched, which are prime locations for persistent malware like bootkits or rootkits to reside. Reinstalling the OS over a quick format would therefore risk reinfection from any malware still present in these unformatted regions, failing to resolve the underlying performance issue if it's malware-related.

  • Use a secure erase utility that overwrites the entire drive including the boot sector.

    Why this is correct

    A secure erase utility performs a low-level overwrite of the entire storage device, including the Master Boot Record (MBR) or GUID Partition Table (GPT), all partitions, and every data sector. This comprehensive process ensures that any persistent malware, such as bootkits or rootkits that embed themselves in the boot sector or unallocated space, is completely eradicated. By completely sanitizing the drive, it provides a clean slate for a fresh operating system installation, effectively eliminating the source of the reported slow performance if caused by deeply embedded malicious software.

  • Delete the encrypted files and run a registry cleaner.

    Why it's wrong here

    Deleting encrypted files, while potentially removing some data, does not address the presence of malware itself, especially if it's a bootkit or rootkit operating at a lower level. Furthermore, running a registry cleaner primarily targets orphaned or invalid entries within the Windows Registry, which might offer minor performance improvements but will not detect or remove active malicious code. Neither action impacts the boot sector or other critical system areas where persistent malware often hides, making this approach insufficient for resolving a potentially severe infection causing slow performance.

  • Use System Restore to revert to a previous state.

    Why it's wrong here

    System Restore is designed to revert system files, registry settings, and installed applications to a previous snapshot, which can sometimes resolve issues caused by recent software installations or configuration changes. However, it is not a comprehensive malware removal tool and often fails to detect or eliminate sophisticated malware, particularly bootkits or rootkits that infect the boot sector or operate outside the scope of the protected system files. Such deeply embedded threats would likely persist even after a System Restore, continuing to cause performance degradation.

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.