Courseiva
Software Troubleshooting →easyMultiple Choice

220-1102 Software Troubleshooting Practice Question

A user's Windows 10 computer was infected with a virus that prevented the antivirus software from running. The technician booted into Safe Mode, ran a full antivirus scan, and successfully removed the virus. However, the user continues to see pop-up advertisements. Which of the following should the technician do NEXT?

⚠ Common exam trap

A common mix-up: candidates assume a full antivirus scan in Safe Mode removes all threats, but adware and PUPs often evade detection or are not classified as viruses, so the technician must manually check browser extensions and startup programs to fully eradicate the pop-up issue.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check browser extensions and startup programs

After removing the virus, persistent pop-up advertisements typically indicate adware or a potentially unwanted program (PUP) that was not removed by the antivirus scan. Checking browser extensions and startup programs targets common persistence mechanisms: malicious browser extensions that inject ads and startup entries that launch adware processes. This step addresses the root cause of the pop-ups without unnecessary system-level repairs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run System File Checker (SFC) and DISM

    Why it's wrong here

    System File Checker (SFC) and Deployment Image Servicing and Management (DISM) are built-in Windows utilities designed to verify and repair the integrity of operating system files and the Windows image. Pop-up advertisements that suddenly appear are almost always the result of adware running as a browser extension, a scheduled task, or a startup entry, not from corrupted core system files. While these tools can fix blue-screen or missing-file issues, they will not remove the adware's persistence mechanisms and are therefore the wrong first step here.

  • ✓

    Check browser extensions and startup programs

    Why this is correct

    Adware commonly installs a browser extension or add-on that injects advertisements into web pages, or it creates a startup program that launches a background process to display pop-ups. In Windows 10, you can inspect installed browser extensions in each browser's add-on manager, and then check startup programs via Task Manager's Startup tab or the System Configuration tool (MSConfig). Removing the malicious extension and disabling any unknown startup entry directly addresses the adware's means of persistence, making this the most targeted and effective initial remediation.

  • ✗

    Reinstall the operating system

    Why it's wrong here

    Reinstalling the operating system is a comprehensive, time-consuming procedure that requires backing up user data, reinstalling all applications, and reconfiguring settings, and it should be reserved for cases where the system is severely damaged or cannot be remediated. Since the infection here is limited to adware, which is a low-severity potentially unwanted program, less invasive removal steps will completely eliminate it without the risk of data loss. Performing a full wipe-and-load before trying targeted removal is an operational overreaction, not a proportional security response.

  • ✗

    Perform a system restore

    Why it's wrong here

    Windows System Restore reverts selected system files, registry keys, and installed programs back to an earlier restore point, but it does not generally remove data or user-profile-level changes such as browser extensions or settings in the current user's AppData folder. If the adware was installed before the chosen restore point, or if its executable lives in a user profile directory that System Restore does not track, it will persist after the restore. By attempting a rollback rather than directly removing the adware from the browser and startup locations, you risk leaving the infection intact and wasting time.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.