220-1102 Security Practice Question
A user reports that their web browser is being redirected to a different search engine and that new toolbars have appeared without their consent. The technician suspects a browser hijacker. Which of the following is the BEST first step to resolve this issue?
⚠ Common exam trap
The trap here is assuming that clearing cookies or reinstalling the browser will fix the hijack, when the malware often persists in system files or registry entries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a full antivirus scan and then reset the browser settings to default.
A browser hijacker modifies browser settings and may install malicious components. Running a full antivirus scan removes the underlying malware, and resetting the browser to default eliminates the unwanted changes. This combined approach ensures both the cause and the symptoms are addressed, providing a clean and secure browser environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manually delete all browser cookies and clear the cache.
Why it's wrong here
Clearing cookies and cache removes temporary data but does not eliminate the malicious extension, toolbar, or changed search settings that cause the redirects. The hijacker typically modifies browser configuration files and registry entries, so this step alone will not resolve the issue.
- ✗
Uninstall and reinstall the web browser.
Why it's wrong here
Reinstalling the browser may not remove the hijacker because the malware could reside in other locations, such as the registry or system files, and could re-infect the new installation. It also does not guarantee removal of malicious extensions that sync with a user profile, so the redirects may persist after reinstallation.
- ✓
Run a full antivirus scan and then reset the browser settings to default.
Why this is correct
A full antivirus scan helps detect and remove any malware components, and resetting the browser settings removes unwanted extensions, toolbars, and search engine changes. This two-step approach addresses both the infection and the persistent configuration changes typical of a browser hijacker, restoring the browser to a clean state.
- ✗
Update the browser to the latest version and enable automatic updates.
Why it's wrong here
Updating the browser patches vulnerabilities but does not remove an existing hijacker. The malicious changes are already in place, and updating alone will not revert them. While updates are important for prevention, they are not the first remediation step for an active infection.
Visual reference
Go deeper
Related to this question
Learn chapter
Malware Classification: Virus, Worm, Ransomware, Rootkit
Key term
Antivirus
Antivirus is software that detects, prevents, and removes malicious software (malware) from a computer or network.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.