Courseiva
Applications and Software →mediumMultiple Select

FC0-U71 Applications and Software Practice Question

A system administrator is evaluating antivirus software for company computers. Which TWO features are most important for protecting against malware? (Select TWO.)

⚠ Common exam trap

FC0-U71 often tests the confusion between network-security features (VPN, firewall) and endpoint malware protection — candidates who pick firewall or VPN miss that only real-time scanning and signature updates directly defend against malware.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Real-time scanning

Option C (Real-time scanning) is correct because it continuously monitors files, processes, and memory as they are accessed or executed, allowing the antivirus to block malware before it can run or spread on the endpoint. Option D (Automatic signature updates) is correct because antivirus detection depends on current malware definitions and heuristics; automatic updates ensure the software recognizes newly discovered threats without manual intervention. Option A (VPN support) is not a core antivirus protection feature, as a VPN primarily encrypts network traffic and masks IP addresses rather than detecting or removing malware. Option B (Email spam filtering) can reduce phishing and malicious attachments but is typically a separate email-security function and not one of the two most essential antivirus capabilities. Option E (Built-in firewall) controls network traffic by filtering ports and connections, which is complementary host protection but distinct from malware scanning and signature-based detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Virtual private network (VPN) support

    Why it's wrong here

    A VPN encrypts traffic in transit between endpoints; it neither scans files nor removes malicious code, so it cannot detect malware on company computers. It is tempting because VPNs protect data confidentiality over untrusted networks, and would be the right choice when remote workers need secure tunnelling to internal resources.

  • ✗

    Email spam filtering

    Why it's wrong here

    Spam filtering blocks unwanted messages at the mail gateway, but it does not scan executables or files already on endpoints, so it cannot detect or remove malware there. It is tempting because filtering reduces phishing-borne infections, and would be correct when securing an email server against bulk unsolicited mail.

  • ✓

    Real-time scanning

    Why this is correct

    Real-time scanning inspects files as they are opened, downloaded or executed, intercepting malware before it can run. This satisfies the stem's protection requirement by blocking threats at the moment of access, rather than relying solely on periodic manual scans that leave infection windows open.

  • ✓

    Automatic signature updates

    Why this is correct

    Automatic signature updates continuously refresh the malware definitions the antivirus engine matches against, so newly released threats are detected without administrator intervention. This satisfies the stem's protection requirement by keeping detection current against rapidly evolving malware, which static, outdated signatures would miss.

  • ✗

    Built-in firewall

    Why it's wrong here

    A firewall filters network traffic by port and address; it does not inspect files for viral signatures or quarantine infected executables, so endpoint malware escapes it. It is tempting because firewalls block unauthorised inbound connections, and would be correct when segmenting network perimeters or restricting which services are reachable.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This FC0-U71 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.