FC0-U71 Security Practice Question
Which THREE of the following are effective methods to protect against malware infections? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install and maintain antivirus software
Option B is correct because installing and maintaining antivirus software with current signature/definition databases enables detection, blocking, and removal of known malware before it can execute or spread. Option C is correct because a firewall filters inbound and outbound traffic against defined rules, blocking malicious connections, command-and-control callbacks, and unauthorized remote access that malware relies on. Option E is correct because keeping operating systems and applications patched closes known vulnerabilities (e.g., unpatched RCE flaws) that malware exploits to gain initial access or escalate privileges. Option A is wrong because opening all email attachments regardless of sender is a primary malware delivery vector, especially via phishing and malicious macros. Option D is wrong because disabling automatic software updates leaves systems exposed to publicly known exploits that vendors have already fixed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Open all email attachments regardless of sender
Why it's wrong here
Opening every attachment bypasses the email gateway's scanning and lets users execute malicious payloads themselves. It is tempting because attachments are how work arrives, and opening them is routine; the correct practise is verifying the sender and scanning files, not treating sender identity as a trust signal.
- ✓
Install and maintain antivirus software
Why this is correct
Antivirus software detects, blocks and removes known malware through signature and behavioural scanning, with regular updates catching new threats. Installing and maintaining it provides continuous host-level protection, satisfying the malware prevention requirement in the stem.
- ✓
Use a firewall to filter incoming and outgoing traffic
Why this is correct
A firewall filters inbound and outbound network traffic against defined rules, blocking malicious connections and preventing infected hosts from contacting command-and-control servers. This network-layer control reduces malware delivery and propagation, making it an effective protective measure against infection.
- ✗
Disable automatic software updates to avoid changes
Why it's wrong here
Disabling automatic updates leaves known vulnerabilities unpatched, which enables malware exploitation rather than preventing infection. It is tempting because change control and testing can justify controlled update timing, but that means scheduled patching, not abandoning updates altogether.
- ✓
Keep operating systems and applications up to date
Why this is correct
Patching closes the known vulnerabilities that malware exploits during infection, removing the attack vector before code can execute. This directly satisfies the stem's requirement for an effective protective method, since unpatched operating systems and applications are the primary entry point for most malware.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.