Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports that their web browser frequently redirects to unwanted advertisement pages and pop-ups appear even when browsing trusted websites. The technician runs antivirus and anti-malware scans, removing several potentially unwanted programs (PUPs). After a reboot, the redirects continue. Which of the following should the technician check NEXT?

⚠ Common exam trap

CompTIA often tests the distinction between DNS-based attacks and proxy-based attacks; the trap here is that candidates assume DNS server changes (Option B) are the fix, but the question's context of persistent redirects after PUP removal points to proxy settings as the more specific and direct cause.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check the browser's proxy settings

After removing PUPs, persistent browser redirects often indicate that the malware modified the browser's proxy settings to route traffic through a malicious proxy server. Checking the proxy settings in the browser or Windows Internet Options is the next logical step because the redirects occur at the application layer, independent of system-level DNS or hosts file changes. This is a common post-cleanup persistence mechanism that antivirus scans may not revert.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Check the browser's proxy settings

    Why this is correct

    Browser hijackers frequently execute a local proxy server or point Internet Explorer/Chrome to a rogue proxy using the 'LAN settings' in Windows Internet Options. This intercepted proxy can inject advertisements and redirect requests, so checking and restoring the proxy to 'Automatically detect settings' (or clearing it) is the most direct corrective action. Also inspect the WinHTTP proxy via 'netsh winhttp show proxy' to ensure a system-wide proxy isn't forcing the browser through a malicious relay.

  • ✗

    Change the DNS server settings to a public DNS like 8.8.8.8

    Why it's wrong here

    Changing to a public DNS (8.8.8.8) is a valid remedy for DNS hijacking, where a compromised router or malware changes the resolver to point a legitimate domain to a malicious IP. However, the symptom of unwanted ad redirects is more commonly caused by an HTTP proxy than by DNS, and a rogue proxy operates above the DNS layer—it still receives the request after the address is resolved. DNS changes would not remove or bypass that proxy, so this is a secondary step to try after proxy confirmation.

  • ✗

    Edit the hosts file to remove any malicious entries

    Why it's wrong here

    The hosts file can redirect specific hostnames to chosen IPs, but it only works at the static hostname-to-IP mapping level and requires administrative rights to modify; consequently, it is rarely used by modern ad-injecting malware that prefers browser extensions or proxy settings. Since the hosts file cannot filter or modify HTTP content and only affects the listed domain names, it would not explain redirects across the web. Even if a malicious entry were found, it would address only that one domain rather than the general redirect pattern.

  • ✗

    Reset the Windows Firewall to default settings

    Why it's wrong here

    Resetting Windows Firewall returns its rules to defaults, but the firewall is a packet-filtering component that neither inspects nor alters HTTP payloads, so it cannot inject advertisements or rewrite HTTP requests to cause browser redirects. A compromised proxy or DNS is the actual root cause, while an unruly firewall rule would either block traffic entirely (with no ad redirect) or permit it—it never modifies the destination URL. Resetting the firewall is also risky because it may remove legitimate inbound or outbound rules unrelated to the browsing problem.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.