mediumMultiple Choice
220-1102 Practice Question: During a security incident, a technician…
During a security incident, a technician discovers that a user's computer has a program that hides its processes from Task Manager and allows an attacker to remotely control the system. The technician suspects a rootkit. Which removal method is most effective for a rootkit?
⚠ Common exam trap
CompTIA A+ often tests the misconception that Safe Mode or boot-time scans are sufficient for rootkit removal, but the trap here is that rootkits operate at a lower level than these methods can reliably clean, making a full OS reinstall the only definitive solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reinstall the operating system from a trusted source.
Rootkits operate at a deep level within the operating system, often hooking kernel-mode functions or modifying system files to hide their presence. Reinstalling the OS from a trusted source ensures that all rootkit components, including those embedded in the boot sector or kernel, are completely removed, as no residual malicious code remains. This method is the only guaranteed way to eliminate a rootkit that has compromised the system's integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a system restore to a point before the infection.
Why it's wrong here
System Restore reverts registry and system files but leaves the rootkit's kernel driver and hidden payloads intact, so infection persists. It suits recovering from faulty updates or misconfigurations, not removing kernel-level malware that survives restore points.
- ✗
Use an antivirus boot disk to scan and remove the rootkit.
Why it's wrong here
A boot disk scans the offline filesystem, but a kernel-mode rootkit hooks the running OS, so it can hide from or reinfect that scan. Boot-disk scanning suits offline malware removal generally; rootkits typically demand reimaging from trusted media.
- ✓
Reinstall the operating system from a trusted source.
Why this is correct
Reinstalling from trusted media eliminates the rootkit because kernel-level malware persists below the operating system, surviving standard antivirus scans and in-place repairs. Since the rootkit hides processes and grants remote control, only overwriting the compromised OS removes the malicious kernel components the attacker embedded.
- ✗
Delete the rootkit's files manually in Safe Mode.
Why it's wrong here
Safe Mode still loads a Windows kernel the rootkit can hook, and its hidden files may be protected or regenerate. Manual deletion suits visible, known malware files; a rootkit's kernel-level hooks and hidden components require reimaging or offline removal.
Go deeper
Related to this question
Learn chapter
Linux File System Structure
Key term
Rootkit
A rootkit is a type of malware that hides its presence and the presence of other malicious software on a computer, often by modifying the operating system itself.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.