Courseiva
mediumMultiple ChoiceObjective-mapped

220-1102 Practice Question: That their Windows 10 computer is infected with a…

A user reports that their Windows 10 computer is infected with a virus that keeps reinstalling itself after removal. What should you do to remediate this persistent infection?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Boot from a rescue disc or USB and run an antivirus scan

A virus that reinstalls itself likely has a rootkit or persistent mechanism. Booting from trusted media and scanning the offline system ensures the malware cannot run, allowing complete removal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Run a system restore to a previous restore point

    Why it's wrong here

    Running a System Restore is generally ineffective against sophisticated malware because it primarily reverts system files and registry settings, not all malicious executables or deeply embedded rootkits. Malware can persist in areas not covered by restore points, or even infect the restore points themselves, leading to reinfection upon restoration. Therefore, it does not guarantee complete eradication of the threat.

  • Boot from a rescue disc or USB and run an antivirus scan

    Why this is correct

    Booting from a rescue disc or USB drive is the most effective method because it ensures the infected operating system is not active, preventing the malware from running, hiding, or interfering with the scanning process. This clean boot environment allows the antivirus software to access and thoroughly scan the entire file system, including hidden areas and system files, for complete and unhindered removal of malicious code. This approach bypasses the malware's ability to defend itself, ensuring a comprehensive cleanup.

  • Disable System Restore and then run an antivirus scan in normal mode

    Why it's wrong here

    Disabling System Restore before scanning in normal mode is insufficient because active malware can still evade detection, block antivirus processes, or re-establish itself during a regular Windows boot. While disabling System Restore prevents the malware from potentially reinfecting via old restore points, the core issue of the active infection interfering with the scan remains. The malware can maintain persistence and prevent its complete removal when the operating system it controls is running.

  • Reinstall Windows from the recovery partition

    Why it's wrong here

    Reinstalling Windows from the recovery partition, while effective for guaranteed malware removal, is considered a last resort due to its highly disruptive nature. This process typically leads to the loss of all user data and installed applications, requiring extensive time for backup, reinstallation, and system configuration. Less invasive methods, such as booting from rescue media, should always be attempted first as they are often successful without the significant overhead of a full operating system reinstallation.

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.