220-1102 Security Practice Question
A user reports that their computer is running very slowly and a security pop-up claims the system is infected. The technician runs an antivirus scan which detects a Trojan. The technician quarantines the Trojan. What is the NEXT step in the malware removal process?
⚠ Common exam trap
Many candidates choose to disconnect from the network first (Option D) because they confuse the initial containment step with the post-quarantine cleanup phase, but the CompTIA malware removal process specifies scanning in Safe Mode after quarantine.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Boot into Safe Mode and run a full antivirus scan
After quarantining the Trojan, the next step is to boot into Safe Mode and run a full antivirus scan. Safe Mode loads only essential drivers and services, preventing the Trojan from running or hiding from detection, which allows the antivirus to find and remove any remaining components or associated malware.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restore the system from a recent backup
Why it's wrong here
Restoring from a recent backup is a recovery action that assumes you have a clean, known-good snapshot and is typically performed only after active infection remediation has failed. It is not the immediate next step after quarantine because a full scan has not yet identified or removed the malware, and restoring could reintroduce the same infected files or lose recent user data. Quarantine itself contains the threat, but the system remains compromised until the infection is actively eliminated, so a fresh restore is premature.
- ✓
Boot into Safe Mode and run a full antivirus scan
Why this is correct
Booting into Safe Mode is the correct immediate step because Windows loads only essential drivers and services, preventing most malware from starting its processes, kernel hooks, or self-protection mechanisms. This stripped-down environment enables the antivirus engine to enumerate the filesystem, registry, and running processes without the malware actively hiding, restoring, or interfering with the scan. Running a full scan from Safe Mode increases detection reliability, especially for persistent threats like rootkits and trojans that inject into normal system processes.
- ✗
Reinstall the operating system
Why it's wrong here
Reinstalling the operating system is an extreme remediation reserved for cases where malware has irreparably corrupted system files, installed a bootkit, or otherwise made cleaning impossible. It is drastic because it destroys all installed programs, user profiles, and data on the system drive, requiring a full reconfiguration and often resulting in data loss. While it guarantees a clean system, it should never be the first action after quarantine because a simple scan and removal attempt is far less invasive and can quickly resolve most infections.
- ✗
Disconnect the computer from the network and continue scanning
Why it's wrong here
Disconnecting the computer from the network is a vital containment step to stop the malware from phoning home to a command-and-control server or spreading to other devices, but it does not address the active infection. Continuing to scan in normal Windows mode is flawed because the malware's processes are still running in memory, allowing it to hide files, alter scan results, or even re-infect the system after a reboot. The proper sequence is to quarantine, disconnect from the network, then boot into Safe Mode, where the malware is dormant, and run a full scan.
Go deeper
Related to this question
Learn chapter
TPM and Secure Boot
Key term
Safe Mode
Safe Mode is a diagnostic startup mode in operating systems that loads only essential drivers and services, allowing users to troubleshoot and fix problems caused by non-critical software or hardware.
Key term
Antivirus
Antivirus is software that detects, prevents, and removes malicious software (malware) from a computer or network.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.