Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports that their computer is running very slowly and a security pop-up claims the system is infected. The technician runs an antivirus scan which detects a Trojan. The technician quarantines the Trojan. What is the NEXT step in the malware removal process?

⚠ Common exam trap

Many candidates choose to disconnect from the network first (Option D) because they confuse the initial containment step with the post-quarantine cleanup phase, but the CompTIA malware removal process specifies scanning in Safe Mode after quarantine.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Boot into Safe Mode and run a full antivirus scan

After quarantining the Trojan, the next step is to boot into Safe Mode and run a full antivirus scan. Safe Mode loads only essential drivers and services, preventing the Trojan from running or hiding from detection, which allows the antivirus to find and remove any remaining components or associated malware.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restore the system from a recent backup

    Why it's wrong here

    Restoring from a recent backup is a recovery action that assumes you have a clean, known-good snapshot and is typically performed only after active infection remediation has failed. It is not the immediate next step after quarantine because a full scan has not yet identified or removed the malware, and restoring could reintroduce the same infected files or lose recent user data. Quarantine itself contains the threat, but the system remains compromised until the infection is actively eliminated, so a fresh restore is premature.

  • ✓

    Boot into Safe Mode and run a full antivirus scan

    Why this is correct

    Booting into Safe Mode is the correct immediate step because Windows loads only essential drivers and services, preventing most malware from starting its processes, kernel hooks, or self-protection mechanisms. This stripped-down environment enables the antivirus engine to enumerate the filesystem, registry, and running processes without the malware actively hiding, restoring, or interfering with the scan. Running a full scan from Safe Mode increases detection reliability, especially for persistent threats like rootkits and trojans that inject into normal system processes.

  • ✗

    Reinstall the operating system

    Why it's wrong here

    Reinstalling the operating system is an extreme remediation reserved for cases where malware has irreparably corrupted system files, installed a bootkit, or otherwise made cleaning impossible. It is drastic because it destroys all installed programs, user profiles, and data on the system drive, requiring a full reconfiguration and often resulting in data loss. While it guarantees a clean system, it should never be the first action after quarantine because a simple scan and removal attempt is far less invasive and can quickly resolve most infections.

  • ✗

    Disconnect the computer from the network and continue scanning

    Why it's wrong here

    Disconnecting the computer from the network is a vital containment step to stop the malware from phoning home to a command-and-control server or spreading to other devices, but it does not address the active infection. Continuing to scan in normal Windows mode is flawed because the malware's processes are still running in memory, allowing it to hide files, alter scan results, or even re-infect the system after a reboot. The proper sequence is to quarantine, disconnect from the network, then boot into Safe Mode, where the malware is dormant, and run a full scan.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.