220-1102 Security Practice Question
A user reports that their workstation is displaying a pop-up message claiming to be from 'Microsoft Support' stating that the computer is infected and to call a toll-free number. The user called the number and allowed remote access, after which the computer began acting erratically. The technician has run an antivirus scan which removed some PUPs but the issue persists. Which additional step should the technician take to secure the system?
⚠ Common exam trap
It's easy for candidates to choose 'Reinstall the operating system' (Option C) as the most secure option, but the CompTIA 220-1102 exam emphasizes that restoring from a known-good backup is the preferred recovery step when available, as it is faster and preserves user data and settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restore from a known-good backup
The user allowed remote access to a scammer, which likely resulted in the installation of malware, backdoors, or unauthorized configuration changes that a standard antivirus scan cannot fully reverse. Restoring from a known-good backup (taken before the incident) ensures the system is returned to a clean state without relying on potentially compromised restore points or incomplete removal. This is the most reliable method to eliminate persistent threats and undo any unauthorized changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable System Restore
Why it's wrong here
Disabling System Restore is a preparatory step that deletes all restore points, including any that might contain infected files, but it does nothing to remove the active malware currently running in memory and on disk. Without an additional cleanup step, the infection persists, and you have also destroyed potentially clean restore points that could have recovered the system. As a standalone remediation action, it is insufficient and counterproductive if a valid restore point exists.
- ✓
Restore from a known-good backup
Why this is correct
Restoring from a known-good backup taken before the infection returns the entire system volume, including the registry, boot files, and user data, to a state that is confirmed free of malware. This eliminates both the initial infection and any persistence mechanisms that may have modified system structures, making it the most reliable recovery option available. It preserves installed applications and user settings while ensuring no malicious payload remains.
- ✗
Reinstall the operating system
Why it's wrong here
Reinstalling the operating system is an aggressive but effective way to eradicate malware, because it reformats the system drive and replaces all OS files with a pristine set. However, it is time-consuming, requires reinstalling every application, and necessitates restoring user data from an external source that could itself be infected. If a recent verified-clean backup exists, a restore is far quicker and preserves the existing environment, making reinstallation a last resort rather than the preferred choice.
- ✗
Run System File Checker
Why it's wrong here
System File Checker (sfc /scannow) validates the integrity of protected system files and repairs any that are corrupted by replacing them with cached copies from the Windows component store. Malware is not a corrupted system file; it is a program or service that must be detected and removed by security software or a system reset. SFC may repair files that malware has altered, but the live malware remains active and can simply re-infect the repaired files, so it provides no direct remediation.
Go deeper
Related to this question
Learn chapter
Physical Security: Locks, Cameras, Access Badges
Key term
Antivirus
Antivirus is software that detects, prevents, and removes malicious software (malware) from a computer or network.
Key term
Backup
A backup is a copy of computer data taken and stored separately so that the original data can be restored if it is lost, damaged, or corrupted.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.