220-1102 Software Troubleshooting Practice Question
A user reports that their Windows 10 Pro laptop suddenly shows a black screen with the message 'This copy of Windows is not genuine' and the desktop background has turned black. The user insists they never changed any hardware. A technician suspects a specific type of malware that modifies the boot sector or system files to bypass activation. Which of the following is the MOST likely type of malware involved?
⚠ Common exam trap
The trap here is assuming that a 'not genuine' message always indicates a hardware change or a licensing issue, when malware like a rootkit can also tamper with activation components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rootkit
A rootkit operates at a low level, modifying system files and boot records to conceal itself, which can interfere with Windows activation checks and produce a 'not genuine' notification. Since the user did not change hardware, the sudden activation failure strongly suggests a rootkit infection rather than other malware types that focus on encryption, disguise, or data theft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Rootkit
Why this is correct
A rootkit can modify system files and boot records to hide its presence and may tamper with Windows activation components, triggering a 'not genuine' notification. Because the user did not change hardware, a rootkit is the most likely malware type to cause this activation-related symptom.
- ✗
Spyware
Why it's wrong here
Spyware secretly monitors user activity and collects information, but it does not typically modify activation status or cause a 'not genuine' error. The symptom described is a system integrity issue, not a privacy breach, so spyware is not the best fit.
- ✗
Trojan
Why it's wrong here
A Trojan disguises itself as legitimate software but usually does not directly alter Windows activation or display a 'not genuine' message. While Trojans can download other malware, the immediate symptom points to a deeper system modification, making a Trojan less likely than a rootkit.
- ✗
Ransomware
Why it's wrong here
Ransomware encrypts files and demands payment, but it does not typically alter Windows activation status or display a 'not genuine' message. In this scenario, the user's files are not reported as encrypted or inaccessible, and the symptom is specifically about activation, so ransomware is not the cause.
Go deeper
Related to this question
Learn chapter
User Account Control (UAC)
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.