220-1102 Software Troubleshooting Practice Question
A technician is troubleshooting a Windows 10 workstation that continues to exhibit malware symptoms—pop-ups, slow performance, and redirected web searches—even after a full antivirus scan removed several threats. The technician suspects a rootkit. Which of the following should the technician perform NEXT to address this specific type of malware?
⚠ Common exam trap
A common mix-up: candidates choose 'Reinstall Windows' (Option B) as the definitive solution, but the exam tests the CompTIA troubleshooting methodology where the least destructive and most efficient step should be performed next, not the nuclear option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a boot-time scan using the antivirus software
A rootkit is designed to hide from the operating system and standard antivirus scans by loading before the OS kernel. A boot-time scan runs before the OS fully loads, allowing the antivirus to detect and remove the rootkit while it is still exposed and unable to hide its processes or files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a system restore to a point before the infection
Why it's wrong here
System Restore reverts critical system files and registry settings to a chosen restore point, but it does not touch the Master Boot Record, boot sector, or kernel-mode drivers where a rootkit often resides. Furthermore, if the rootkit was active when the restore point was created, it may be preserved inside a shadow copy and be reinstated upon rollback. For a suspected rootkit, the appropriate next step is a boot-time antivirus scan, not a restore.
- ✗
Reinstall Windows to completely remove the rootkit
Why it's wrong here
Reinstalling Windows will indeed remove most OS-level rootkits, but it is an irreversible and time-consuming action that destroys user data and installed applications. It must be reserved as a last resort after less invasive options like a boot-time scan with current antivirus signatures have failed. Additionally, if the rootkit persists in the UEFI firmware or a system BIOS flash, a standard OS reinstall alone will not eliminate it, requiring specialized firmware-reset procedures. Thus, it is not the correct immediate action when a rootkit is suspected.
- ✗
Disable startup programs from Task Manager
Why it's wrong here
Task Manager's Startup tab lists only user- and application-triggered startup entries, typically via the Run registry keys or the shell Startup folder; it does not enumerate boot-start services or kernel-mode drivers. A rootkit generally loads as a boot driver or hooks system calls through direct kernel-object manipulation, starting far earlier than any user-level application. Disabling such startup programs leaves the rootkit untouched and able to continue its stealthy operation, making this action ineffective for the reported issue.
- ✓
Run a boot-time scan using the antivirus software
Why this is correct
A boot-time scan runs from a pre-OS environment, such as a rescue disk or the built-in Windows Defender offline feature, before the operating system kernel and device drivers are loaded. Because the rootkit has not yet gained control of the OS, it cannot hide its files, processes, or registry entries from the scanner, permitting detection and removal without interference. This is the recommended first step against a suspected rootkit because it directly targets the infection's stealth mechanism and has a high chance of eradicating it without a full reinstallation.
Go deeper
Related to this question
Learn chapter
System File Checker (sfc /scannow)
Key term
Operating system
An operating system (OS) is the core software that manages a computer's hardware and software resources, providing common services for computer programs.
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.