220-1102 Software Troubleshooting Practice Question
A user's Windows 10 computer was infected with a virus that prevented the antivirus software from running. The technician booted into Safe Mode, ran a full antivirus scan, and successfully removed the virus. However, the user continues to see pop-up advertisements. Which of the following should the technician do NEXT?
⚠ Common exam trap
A common mix-up: candidates assume a full antivirus scan in Safe Mode removes all threats, but adware and PUPs often evade detection or are not classified as viruses, so the technician must manually check browser extensions and startup programs to fully eradicate the pop-up issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check browser extensions and startup programs
After removing the virus, persistent pop-up advertisements typically indicate adware or a potentially unwanted program (PUP) that was not removed by the antivirus scan. Checking browser extensions and startup programs targets common persistence mechanisms: malicious browser extensions that inject ads and startup entries that launch adware processes. This step addresses the root cause of the pop-ups without unnecessary system-level repairs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run System File Checker (SFC) and DISM
Why it's wrong here
System File Checker (SFC) and Deployment Image Servicing and Management (DISM) are built-in Windows utilities designed to verify and repair the integrity of operating system files and the Windows image. Pop-up advertisements that suddenly appear are almost always the result of adware running as a browser extension, a scheduled task, or a startup entry, not from corrupted core system files. While these tools can fix blue-screen or missing-file issues, they will not remove the adware's persistence mechanisms and are therefore the wrong first step here.
- ✓
Check browser extensions and startup programs
Why this is correct
Adware commonly installs a browser extension or add-on that injects advertisements into web pages, or it creates a startup program that launches a background process to display pop-ups. In Windows 10, you can inspect installed browser extensions in each browser's add-on manager, and then check startup programs via Task Manager's Startup tab or the System Configuration tool (MSConfig). Removing the malicious extension and disabling any unknown startup entry directly addresses the adware's means of persistence, making this the most targeted and effective initial remediation.
- ✗
Reinstall the operating system
Why it's wrong here
Reinstalling the operating system is a comprehensive, time-consuming procedure that requires backing up user data, reinstalling all applications, and reconfiguring settings, and it should be reserved for cases where the system is severely damaged or cannot be remediated. Since the infection here is limited to adware, which is a low-severity potentially unwanted program, less invasive removal steps will completely eliminate it without the risk of data loss. Performing a full wipe-and-load before trying targeted removal is an operational overreaction, not a proportional security response.
- ✗
Perform a system restore
Why it's wrong here
Windows System Restore reverts selected system files, registry keys, and installed programs back to an earlier restore point, but it does not generally remove data or user-profile-level changes such as browser extensions or settings in the current user's AppData folder. If the adware was installed before the chosen restore point, or if its executable lives in a user profile directory that System Restore does not track, it will persist after the restore. By attempting a rollback rather than directly removing the adware from the browser and startup locations, you risk leaving the infection intact and wasting time.
Go deeper
Related to this question
Learn chapter
System Restore Points
Key term
Virus
A virus is a malicious software program that attaches itself to legitimate files or programs and spreads to other systems, often causing damage or stealing information.
Key term
Safe Mode
Safe Mode is a diagnostic startup mode in operating systems that loads only essential drivers and services, allowing users to troubleshoot and fix problems caused by non-critical software or hardware.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.