Courseiva
mediumMultiple ChoiceObjective-mapped

220-1102 Practice Question: That their Windows 10 PC is infected with a virus…

A user reports that their Windows 10 PC is infected with a virus that changes the desktop background to a ransom note. After removing the virus with antivirus software, the desktop background remains unchanged. What should you do to restore the original background?

⚠ Common exam trap

A common mix-up: candidates assume a virus removal or system file repair will fix all remnants of the infection, but they overlook that malware can modify persistent system policies like Group Policy, which require explicit reversal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Check Group Policy settings for desktop wallpaper enforcement and reset them.

The virus likely modified the Group Policy setting that enforces a specific desktop wallpaper. Even after the virus is removed, the Group Policy setting persists and overrides any user attempts to change the background. Resetting the Group Policy wallpaper enforcement restores the user's ability to change the background normally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Reinstall the graphics driver.

    Why it's wrong here

    Reinstalling the graphics driver is ineffective because the issue is not related to display rendering or hardware interaction. A graphics driver's function is to enable the operating system to communicate with the video card and display images correctly. When a desktop wallpaper is locked by a policy, the display hardware and its driver are functioning as intended, simply presenting the enforced background as dictated by the operating system's configuration, not due to a driver malfunction or corruption.

  • Run System File Checker (sfc /scannow).

    Why it's wrong here

    Running System File Checker (sfc /scannow) is designed to scan for and repair corrupted Windows system files, restoring them to their original versions. While crucial for maintaining OS integrity, Group Policy settings, even those maliciously altered, are typically stored within the Windows Registry and specific policy files, not as core system files that SFC would validate or repair. Therefore, SFC would not address or revert a Group Policy restriction on the desktop background.

  • Check Group Policy settings for desktop wallpaper enforcement and reset them.

    Why this is correct

    Malware frequently modifies Group Policy settings to enforce its presence, restrict user actions, or maintain persistence, such as preventing users from changing their desktop wallpaper. These specific policies, often found under User Configuration > Administrative Templates > Desktop > Desktop in the Local Group Policy Editor (gpedit.msc), can enforce a specific background image or disable the ability to change it. Identifying and then disabling or setting such a policy to 'Not Configured' will restore the user's ability to customize their desktop background.

  • Perform a system restore to a point before the infection.

    Why it's wrong here

    Performing a system restore aims to revert system files, installed applications, and registry settings to a previous state, which can sometimes remove malware. However, its effectiveness in reverting Group Policy changes can be inconsistent. Some Group Policy modifications, especially those applied persistently or through specific scripts, might not be fully captured or reverted by a System Restore point. Directly addressing the policy is a more precise and often more reliable solution than a potentially incomplete system-wide rollback.

Go deeper

Related to this question

About these practice questions

This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.