Courseiva
Software Troubleshooting →mediumMultiple Choice

220-1102 Software Troubleshooting Practice Question

A user reports that their Windows 10 Pro laptop suddenly shows a black screen with the message 'This copy of Windows is not genuine' and the desktop background has turned black. The user insists they never changed any hardware. A technician suspects a specific type of malware that modifies the boot sector or system files to bypass activation. Which of the following is the MOST likely type of malware involved?

⚠ Common exam trap

The trap here is assuming that a 'not genuine' message always indicates a hardware change or a licensing issue, when malware like a rootkit can also tamper with activation components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rootkit

A rootkit operates at a low level, modifying system files and boot records to conceal itself, which can interfere with Windows activation checks and produce a 'not genuine' notification. Since the user did not change hardware, the sudden activation failure strongly suggests a rootkit infection rather than other malware types that focus on encryption, disguise, or data theft.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Rootkit

    Why this is correct

    A rootkit can modify system files and boot records to hide its presence and may tamper with Windows activation components, triggering a 'not genuine' notification. Because the user did not change hardware, a rootkit is the most likely malware type to cause this activation-related symptom.

  • ✗

    Spyware

    Why it's wrong here

    Spyware secretly monitors user activity and collects information, but it does not typically modify activation status or cause a 'not genuine' error. The symptom described is a system integrity issue, not a privacy breach, so spyware is not the best fit.

  • ✗

    Trojan

    Why it's wrong here

    A Trojan disguises itself as legitimate software but usually does not directly alter Windows activation or display a 'not genuine' message. While Trojans can download other malware, the immediate symptom points to a deeper system modification, making a Trojan less likely than a rootkit.

  • ✗

    Ransomware

    Why it's wrong here

    Ransomware encrypts files and demands payment, but it does not typically alter Windows activation status or display a 'not genuine' message. In this scenario, the user's files are not reported as encrypted or inaccessible, and the symptom is specifically about activation, so ransomware is not the cause.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.