Courseiva
easyMultiple Choice

220-1102 Practice Question: That their Windows 10 computer is displaying a…

A user reports that their Windows 10 computer is displaying a message that 'Windows Defender Antivirus is turned off' even though they have not disabled it. They have also noticed that they cannot open the Windows Security app. What is the most likely cause?

⚠ Common exam trap

Candidates may incorrectly attribute this to Group Policy (Option A) because the symptom resembles a managed environment, but malware can achieve the same effect locally. The inability to open the Windows Security app is a key differentiator that points to infection rather than policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The computer is infected with malware

When a user sees 'Windows Defender Antivirus is turned off' and cannot open the Windows Security app, the most likely cause is malware that has disabled the antivirus and blocked access to security settings to prevent removal. Malware often modifies registry keys or terminates Windows Defender services (e.g., WinDefend) to evade detection, and it may also corrupt or block the Windows Security Center UI (SecurityHealthService.exe). This is a common symptom of ransomware or trojans that specifically target Windows Defender.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Windows Defender is disabled via Group Policy

    Why it's wrong here

    Group Policy disabling Defender would normally grey out options within Windows Security, not prevent the app itself from launching. It is tempting because policy is a common cause of disabled protection, but a third-party antivirus registering with Security Center explains both symptoms together.

  • ✓

    The computer is infected with malware

    Why this is correct

    Malware can disable Windows Defender and block the Windows Security app, producing exactly the reported symptoms. This satisfies the stem's constraint: protection switched off without user action, plus an unopenable Security app. Rogue security software and some trojans specifically target these components to evade detection, so infection is the most likely cause.

  • ✗

    Windows needs a critical update

    Why it's wrong here

    Malware disabling Defender and blocking the Windows Security app is the likely cause, not a pending update; updates trigger prompts but do not lock the Security UI. A critical update is tempting because patching restores Defender after component corruption, yet it cannot explain the inaccessible Security app.

  • ✗

    User Account Control is blocking the app

    Why it's wrong here

    User Account Control prompts for elevation; it does not silently block the Windows Security app from opening. It is tempting because UAC governs privileged actions, yet the combination of Defender reporting off and the app failing to launch points to a third-party antivirus taking over protection.

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.