easyMultiple Choice
220-1102 Practice Question: That their workstation is running slowly and they…
A user reports that their workstation is running slowly and they see frequent pop-up ads even when no browser is open. They also notice a new toolbar in their system tray that they did not install. What is the most likely security issue?
⚠ Common exam trap
The distinction between adware and other malware types is a common test point in CompTIA A+. Candidates may confuse adware with a rootkit because both can be persistent, but rootkits are stealthy and do not produce visible ads or toolbars.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The system has adware installed.
Adware is a type of malware that displays unwanted advertisements, often in the form of pop-ups or browser redirects, and may install toolbars or other unwanted software without the user's consent. The presence of a new toolbar in the system tray and frequent pop-ups even when no browser is open are classic indicators of adware infection, as adware often runs background processes to generate revenue through ad impressions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A rootkit has hidden itself in the kernel.
Why it's wrong here
A rootkit conceals existing compromise through kernel-level hooks; it does not itself inject browser pop-ups or install visible toolbars. Rootkits are the right answer when standard scans and Task Manager reveal nothing despite confirmed compromise, but the overt adware symptoms here point elsewhere.
- ✓
The system has adware installed.
Why this is correct
Adware matches the evidence precisely: pop-ups appearing without a browser open indicate a background process injecting advertisements, and the unrequested system-tray toolbar confirms bundled unwanted software. Unlike a virus, adware primarily generates revenue through forced advertising rather than self-replication, satisfying the stem's slow performance and persistent pop-up constraints.
- ✗
A ransomware encryption process has started.
Why it's wrong here
Ransomware encrypts files and displays extortion demands; it does not generate pop-up advertising or add toolbars. Encryption is the right diagnosis when files become inaccessible with renamed extensions, but the described symptoms reflect advertising software running persistently on the host.
- ✗
The user's account has been phished and credentials stolen.
Why it's wrong here
Stolen credentials enable account takeover and fraudulent logins, not local ad injection or unwanted toolbars appearing in the system tray. Phishing is correct when the evidence is suspicious sign-ins or mailbox rules, but these persistent on-screen symptoms indicate installed adware instead.
Go deeper
Related to this question
Learn chapter
Troubleshoot: Malware Infections
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Pop-up ads
Pop-up ads are unsolicited browser windows or overlays that appear automatically while browsing, often used for advertising or, maliciously, to spread malware.
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.