Courseiva
Software Troubleshooting →mediumMultiple Choice

220-1102 Software Troubleshooting Practice Question

A user reports that their Windows 10 workstation is running slowly and displaying pop-up ads frequently. The technician runs a full antivirus scan, which removes several adware programs, but the symptoms persist. The technician also checks the browser extensions and removes suspicious ones. The pop-ups continue. Which step should the technician perform NEXT?

⚠ Common exam trap

Watch out — candidates often choose System Restore (Option A) thinking it will revert the system to a clean state, but they overlook that malware can persist in restore points and that Safe Mode scanning is a more targeted and effective next step for active adware removal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Boot into Safe Mode with Networking and run a malware removal tool

B is correct because booting into Safe Mode with Networking loads only essential drivers and services, preventing many persistent malware components from running, and allows the technician to run a dedicated malware removal tool (e.g., Malwarebytes, Windows Defender Offline) that can detect and remove rootkits or deeply embedded adware that a standard antivirus scan missed. This step isolates the system from active threats while maintaining network access to download updated definitions or specialized tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform a System Restore to a point before the infection

    Why it's wrong here

    System Restore restores registry keys and critical system files to an earlier point, but it does not scan for or actively remove malware. Many infections embed themselves in user profile folders, scheduled tasks, or startup entries that remain untouched by restore points, and malware can also delete or corrupt restore points to avoid removal. Relying on System Restore gives a false sense of remediation while persistent components keep re-infecting the system.

  • ✓

    Boot into Safe Mode with Networking and run a malware removal tool

    Why this is correct

    Booting into Safe Mode with Networking loads only essential drivers and services, which prevents most malware from auto-starting and interfering with cleanup tools. With network access, the technician can update antivirus definitions, download specialized removal utilities, or use cloud-based scanners to identify the threat. This is the appropriate first step because it isolates active infection vectors while preserving the ability to fetch and run the latest remediation tools.

  • ✗

    Perform a clean installation of Windows

    Why it's wrong here

    A clean installation of Windows completely wipes the system drive and reinstalls the OS, which will certainly destroy malware but also removes all user data, installed applications, and custom settings. It is considered a last-resort action after less destructive methods have failed, and performing it prematurely causes unnecessary data loss and downtime. In this scenario, less invasive malware removal should be attempted first, so a clean install is not the correct initial response.

  • ✗

    Disable all non-Microsoft services using MSConfig

    Why it's wrong here

    Disabling non-Microsoft services via MSConfig alters which third-party services launch at boot but does not delete malware files or reverse registry persistence. Many infections hide as scheduled tasks, browser add-ons, or boot-time drivers, which MSConfig does not comprehensively address; moreover, disabling services can break legitimate software and only masks symptoms. The underlying malware remains intact, so pop-ups and poor performance will likely return once the malicious code is triggered again.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.