Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A user reports that their workstation is displaying a pop-up message claiming to be from 'Microsoft Support' stating that the computer is infected and to call a toll-free number. The user called the number and allowed remote access, after which the computer began acting erratically. The technician has run an antivirus scan which removed some PUPs but the issue persists. Which additional step should the technician take to secure the system?

⚠ Common exam trap

It's easy for candidates to choose 'Reinstall the operating system' (Option C) as the most secure option, but the CompTIA 220-1102 exam emphasizes that restoring from a known-good backup is the preferred recovery step when available, as it is faster and preserves user data and settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restore from a known-good backup

The user allowed remote access to a scammer, which likely resulted in the installation of malware, backdoors, or unauthorized configuration changes that a standard antivirus scan cannot fully reverse. Restoring from a known-good backup (taken before the incident) ensures the system is returned to a clean state without relying on potentially compromised restore points or incomplete removal. This is the most reliable method to eliminate persistent threats and undo any unauthorized changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable System Restore

    Why it's wrong here

    Disabling System Restore is a preparatory step that deletes all restore points, including any that might contain infected files, but it does nothing to remove the active malware currently running in memory and on disk. Without an additional cleanup step, the infection persists, and you have also destroyed potentially clean restore points that could have recovered the system. As a standalone remediation action, it is insufficient and counterproductive if a valid restore point exists.

  • ✓

    Restore from a known-good backup

    Why this is correct

    Restoring from a known-good backup taken before the infection returns the entire system volume, including the registry, boot files, and user data, to a state that is confirmed free of malware. This eliminates both the initial infection and any persistence mechanisms that may have modified system structures, making it the most reliable recovery option available. It preserves installed applications and user settings while ensuring no malicious payload remains.

  • ✗

    Reinstall the operating system

    Why it's wrong here

    Reinstalling the operating system is an aggressive but effective way to eradicate malware, because it reformats the system drive and replaces all OS files with a pristine set. However, it is time-consuming, requires reinstalling every application, and necessitates restoring user data from an external source that could itself be infected. If a recent verified-clean backup exists, a restore is far quicker and preserves the existing environment, making reinstallation a last resort rather than the preferred choice.

  • ✗

    Run System File Checker

    Why it's wrong here

    System File Checker (sfc /scannow) validates the integrity of protected system files and repairs any that are corrupted by replacing them with cached copies from the Windows component store. Malware is not a corrupted system file; it is a program or service that must be detected and removed by security software or a system reset. SFC may repair files that malware has altered, but the live malware remains active and can simply re-infect the repaired files, so it provides no direct remediation.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.