Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user's web browser frequently redirects to unfamiliar search engines and displays persistent pop-up ads. The technician runs a full antivirus scan, which removes several threats, but the behavior continues. Upon inspection, the technician finds that the browser's proxy settings have been altered. Which type of malware is most likely responsible?

⚠ Common exam trap

The 220-1102 exam often tests the distinction between adware and trojans by presenting symptoms of browser hijacking (redirects, pop-ups) — candidates mistakenly choose 'Trojan' because they associate any unwanted software with trojans, but the specific behavior of altering proxy settings and persistent ads is the hallmark of adware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

C. Adware

Adware is designed to display unwanted advertisements and redirect web traffic to generate revenue. The persistence of pop-ups and browser redirects even after antivirus removal, combined with altered proxy settings, is a classic sign of adware that modifies browser configurations (e.g., proxy auto-config or manual proxy settings) to intercept and redirect HTTP/HTTPS traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A. Ransomware

    Why it's wrong here

    Ransomware is a type of malware that encrypts a user's files or locks the entire system, then demands a cryptocurrency payment in exchange for decryption or restoration. Its objective is financial extortion rather than generating ad revenue, and it typically does not alter browser proxy or search settings. Therefore, the browsing redirects described do not align with ransomware's primary behavior, although a 'browser locker' variant exists, it still demands ransom rather than silently serving ads.

  • ✗

    B. Trojan

    Why it's wrong here

    A Trojan horse is a malicious program disguised as a legitimate application that, when executed, can provide a backdoor, drop additional malware, or exfiltrate sensitive data. While Trojans are versatile, their core function is stealthy unauthorized access, not modifying browser proxy settings to force advertisement-based redirection. The symptom of an unfamiliar search engine appearing in the browser is more directly caused by adware, which is purpose-built to hijack web sessions for advertising revenue rather than to deliver remote control or data theft.

  • ✓

    C. Adware

    Why this is correct

    Adware is software specifically designed to display unsolicited ads, often by hijacking browser configurations such as the homepage, search engine, or proxy settings. In this scenario, the redirects to unfamiliar search engines occur because adware changes the system proxy or browser search provider to route queries through advertising affiliate links, generating revenue per click. Unlike ransomware or a Trojan, adware's primary goal is advertising monetization, and its behavior is precisely the persistent, browser-centric redirection described in the question.

  • ✗

    D. Rootkit

    Why it's wrong here

    A rootkit is engineered to conceal its own presence and maintain privileged, undetected access to the operating system's kernel or system firmware. Because rootkits prioritize stealth, they avoid causing overt, visible symptoms like browser redirects, which would immediately alert the user that something is wrong. The persistence mechanism of a rootkit is to hide malicious processes and files, not to manipulate user-facing browser settings, so browsing behaviors such as search redirection are not indicative of a rootkit infection.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A user reports that their web browser frequently redirects to unwanted advertisement pages and pop-ups appear even when browsing trusted websites. The technician runs antivirus and anti-malware scans, removing several potentially unwanted programs (PUPs). After a reboot, the redirects continue. Which of the following should the technician check NEXT?

medium
  • ✓ A.Check the browser's proxy settings
  • B.Change the DNS server settings to a public DNS like 8.8.8.8
  • C.Edit the hosts file to remove any malicious entries
  • D.Reset the Windows Firewall to default settings

Why A: After removing PUPs, persistent browser redirects often indicate that the malware modified the browser's proxy settings to route traffic through a malicious proxy server. Checking the proxy settings in the browser or Windows Internet Options is the next logical step because the redirects occur at the application layer, independent of system-level DNS or hosts file changes. This is a common post-cleanup persistence mechanism that antivirus scans may not revert.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.