220-1102 Security Practice Question
A user reports that their Windows 10 workstation suddenly cannot access any network resources. A technician remotely views the system and notices a popup that mimics a Windows Security alert, stating the system is infected. The technician checks the IP configuration and sees the workstation has an APIPA address (169.254.x.x). The network adapter shows no physical link issues. Which of the following is the MOST likely cause of the issue?
⚠ Common exam trap
The trap here is that candidates often associate APIPA only with a missing or unresponsive DHCP server, overlooking the possibility that malware can deliberately disable the DHCP client service to simulate a network outage as part of a social engineering attack.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Malware is disabling the DHCP client service to block internet access as part of a scareware campaign.
The APIPA address (169.254.x.x) indicates the workstation failed to obtain a DHCP lease. The popup mimicking a Windows Security alert is a classic scareware tactic. Malware that disables the DHCP Client service prevents the system from renewing or obtaining an IP address, effectively cutting off network access to pressure the user into purchasing fake security software.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A rogue DHCP server is issuing invalid IP addresses on the network.
Why it's wrong here
A rogue DHCP server on the LAN could indeed respond faster than the legitimate one and hand out an IP in a different subnet or with a bad gateway, which would break connectivity. However, the client would still receive a valid-looking lease from that rogue server, so the adapter would not fall back to APIPA (169.254.x.x). Additionally, a rogue DHCP server is a network-layer threat and does not create a fake Windows Security popup on the local machine, so it fails to explain the full set of symptoms.
- ✗
An ARP poisoning attack is redirecting network traffic, causing the system to lose its lease.
Why it's wrong here
ARP poisoning manipulates the IP-to-MAC address mappings on the local segment, allowing an attacker to intercept or alter traffic between hosts. Because DHCP discovery relies on broadcast frames that are not dependent on ARP cache integrity, an ARP poisoning attack would not prevent the DHCP client from obtaining or renewing a lease; the interface would keep its assigned IP address. Even if connectivity were degraded, the client would not suddenly switch to APIPA, and ARP poisoning alone would not cause a scareware popup to appear.
- ✓
Malware is disabling the DHCP client service to block internet access as part of a scareware campaign.
Why this is correct
Scareware commonly disrupts network access to manufacture a crisis that the malware then offers to 'fix' for a fee. By stopping or disabling the DHCP Client service (DHCPSVC), the network interface can no longer request a lease; Windows then auto-configures an APIPA address in the 169.254.0.0/16 range, producing the 'Limited connectivity' state. At the same time, the malware displays a fake Windows Security alert demanding immediate action, which perfectly matches the reported symptom of no network access plus a popup.
- ✗
A DNS hijack is preventing the workstation from resolving network names, so it falls back to APIPA.
Why it's wrong here
DNS hijacking only corrupts or redirects name resolution, sending the user to malicious IPs or producing NXDOMAIN errors, but it does not alter the local IP configuration. In a DNS hijack scenario, the DHCP client would still run normally and the workstation would retain its assigned lease, so the interface would never fall back to an APIPA address. Therefore, a DNS hijack cannot explain the 169.254.x.x self-assigned IP, and it also would not generate a scareware popup on the desktop.
Visual reference
Go deeper
Related to this question
Learn chapter
SOHO Network Security
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.