220-1102 Security Practice Question
A technician is cleaning a workstation that was infected with a rootkit. The technician has booted into a trusted recovery environment and run anti-malware scans. After removing the rootkit, the technician wants to ensure no remnants remain. Which of the following is the BEST next step?
⚠ Common exam trap
Test-takers frequently assume a thorough scan from a trusted environment is sufficient, but CompTIA emphasizes that rootkits require a full OS reinstall because they can hide from and survive even advanced scanning tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reinstall the operating system
A rootkit operates at the kernel level, often hiding its files, registry entries, and processes from the operating system. Even after running anti-malware scans from a trusted recovery environment, the rootkit may have modified system files or boot components that are not fully restored by scanning alone. Reinstalling the operating system is the only way to guarantee that all remnants, including any hidden or dormant rootkit components, are completely removed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Reinstall the operating system
Why this is correct
A clean installation wipes the entire boot volume, including the MBR/GPT, bootloader, system files, and all user-mode and kernel-mode components, eliminating any persistence mechanisms a rootkit may have installed. Unlike antivirus or removal tools, reimaging does not rely on the integrity of the already-compromised OS, so hidden kernel hooks or firmware-resident payloads are overwritten. For a workstation with a confirmed rootkit, this is the only way to guarantee a known-good state, assuming the installation media itself is trusted and secure.
- ✗
Run a full system restore from a recent backup
Why it's wrong here
A recent backup is suspect because the rootkit may have been present and dormant at the time the backup was created, and many rootkits actively hide their presence from the OS, so the backup could silently reinfect the system. Even if the backup predates the infection, restore operations typically write back the same boot sector, registry hives, and kernel files that the rootkit had already modified. Thus, a restore merely reintroduces the compromised state rather than cleaning it, and it cannot be considered a reliable remediation step.
- ✗
Perform a manual registry cleanup
Why it's wrong here
Rootkits often operate at ring 0 or hook kernel-level APIs, keeping their malicious code in kernel memory, driver files, or boot components, not just in user-accessible registry keys; a registry cleanup can only touch a small portion of the infection surface. Furthermore, the rootkit can actively re-write or hide registry entries while the system is running, and a manual cleanup cannot detect or remove fileless or memory-resident payloads. Without wiping the disk, registry edits leave behind bootkits and other low-level artifacts.
- ✗
Enable Secure Boot in the UEFI
Why it's wrong here
Secure Boot is a UEFI firmware feature that verifies the digital signature of the bootloader and drivers during the boot process, but it only prevents unauthorized code from loading at startup; it does not inspect or remove a rootkit that is already present on the disk. Moreover, many rootkits are already running and are not tied to the boot sequence, or they may have disabled or bypassed Secure Boot, so enabling it after the fact does nothing to eradicate the established infection. It is a preventive control, not a remediation action.
Go deeper
Related to this question
Learn chapter
Malware Types and Removal
Key term
Registry
The Windows Registry is a central hierarchical database that stores configuration settings and options for the operating system, hardware, software, and user preferences.
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.