Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A technician is cleaning a workstation that was infected with a rootkit. The technician has booted into a trusted recovery environment and run anti-malware scans. After removing the rootkit, the technician wants to ensure no remnants remain. Which of the following is the BEST next step?

⚠ Common exam trap

Test-takers frequently assume a thorough scan from a trusted environment is sufficient, but CompTIA emphasizes that rootkits require a full OS reinstall because they can hide from and survive even advanced scanning tools.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reinstall the operating system

A rootkit operates at the kernel level, often hiding its files, registry entries, and processes from the operating system. Even after running anti-malware scans from a trusted recovery environment, the rootkit may have modified system files or boot components that are not fully restored by scanning alone. Reinstalling the operating system is the only way to guarantee that all remnants, including any hidden or dormant rootkit components, are completely removed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reinstall the operating system

    Why this is correct

    A clean installation wipes the entire boot volume, including the MBR/GPT, bootloader, system files, and all user-mode and kernel-mode components, eliminating any persistence mechanisms a rootkit may have installed. Unlike antivirus or removal tools, reimaging does not rely on the integrity of the already-compromised OS, so hidden kernel hooks or firmware-resident payloads are overwritten. For a workstation with a confirmed rootkit, this is the only way to guarantee a known-good state, assuming the installation media itself is trusted and secure.

  • ✗

    Run a full system restore from a recent backup

    Why it's wrong here

    A recent backup is suspect because the rootkit may have been present and dormant at the time the backup was created, and many rootkits actively hide their presence from the OS, so the backup could silently reinfect the system. Even if the backup predates the infection, restore operations typically write back the same boot sector, registry hives, and kernel files that the rootkit had already modified. Thus, a restore merely reintroduces the compromised state rather than cleaning it, and it cannot be considered a reliable remediation step.

  • ✗

    Perform a manual registry cleanup

    Why it's wrong here

    Rootkits often operate at ring 0 or hook kernel-level APIs, keeping their malicious code in kernel memory, driver files, or boot components, not just in user-accessible registry keys; a registry cleanup can only touch a small portion of the infection surface. Furthermore, the rootkit can actively re-write or hide registry entries while the system is running, and a manual cleanup cannot detect or remove fileless or memory-resident payloads. Without wiping the disk, registry edits leave behind bootkits and other low-level artifacts.

  • ✗

    Enable Secure Boot in the UEFI

    Why it's wrong here

    Secure Boot is a UEFI firmware feature that verifies the digital signature of the bootloader and drivers during the boot process, but it only prevents unauthorized code from loading at startup; it does not inspect or remove a rootkit that is already present on the disk. Moreover, many rootkits are already running and are not tied to the boot sequence, or they may have disabled or bypassed Secure Boot, so enabling it after the fact does nothing to eradicate the established infection. It is a preventive control, not a remediation action.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.