exam questions

Exam 220-1102 All Questions

View all questions & answers for the 220-1102 exam

Exam 220-1102 topic 1 question 190 discussion

Actual exam question from CompTIA's 220-1102
Question #: 190
Topic #: 1
[All 220-1102 Questions]

A user is unable to access files on a work PC after opening a text document. The text document was labeled “URGENT PLEASE READ.txt - In active folder, .txt file titled urgent please read”. Which of the following should a support technician do FIRST?

  • A. Quarantine the host in the antivirus system.
  • B. Run antivirus scan for malicious software.
  • C. Investigate how malicious software was installed.
  • D. Reimage the computer.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mehsotopes
Highly Voted 1 year, 8 months ago
Selected Answer: B
The technician has not confirmed that this is malware. if customer is still there, the technician should definitely inquire if the customer knows where that file came from, & what it is. If the customer is not reachable, technician should first scan the computer for viruses.
upvoted 13 times
Mango7
1 year, 6 months ago
I like all your explanations, your reasonings are always on point brother.
upvoted 3 times
...
...
Farticus
Highly Voted 1 year, 11 months ago
Selected Answer: C
The answer would be C. 3.2 of the Comptia 1102 exam objectives states the following: Given a scenario, use best practice procedures for malware removal. 1. Investigate and verify malware symptoms 2.Quarantine infected systems 3.Disable System Restore in Windows 4.Remediate infected systems a. Update anti-malware software b.Scanning and removal techniques (e.g., safe mode, preinstallation environment) 5.Schedule scans and run updates 6.Enable System Restore and create a restore point in Windows 7. Educate the end user
upvoted 9 times
Calebdames
1 year, 10 months ago
So B "1. Investigate and verify malware symptoms" how else do you investigate and verify malware symptons,
upvoted 2 times
ShukazoPenguin
1 year, 4 months ago
C implies that the malware was already discovered, so it's B.
upvoted 2 times
...
...
...
Nickem10Times
Most Recent 2 weeks, 4 days ago
Selected Answer: A
Selecting A because the user already can't access files after opening the suspicious document. The next step in the CompTIA’s malware removal best practices prioritize containment first. If the system remains active while you investigate or run scans, the malware could: 1. Spread across the network 2. Encrypt more files (if it's ransomware) 3. Exfiltrate sensitive data This is why A seems correct to me.
upvoted 1 times
...
dickchappy
6 months, 3 weeks ago
Selected Answer: B
You have not yet verified that there is malware on the system, so it would have to be B. Investigating how it was installed would be one of the last things you do as part of educating the user.
upvoted 1 times
...
Philco
8 months ago
C there is a mind change-------after reading the question again
upvoted 1 times
...
Philco
8 months ago
A why is it not A-- according to Comptia "best practice procedures for malware removal".and assuming it is some kind of malware, it should be Quarantine infected system 1. Investigate and verify malware symptoms 2.Quarantine infected systems 3.Disable System Restore in Windows 4.Remediate infected systems a. Update anti-malware software b.Scanning and removal techniques (e.g., safe mode, preinstallation environment) 5.Schedule scans and run updates 6.Enable System Restore and create a restore point in Windows 7. Educate the end user
upvoted 1 times
...
saraperales
8 months, 1 week ago
Selected Answer: B
It's B
upvoted 2 times
...
Phillyboy20_
11 months ago
Selected Answer: B
The question doesn't mention that it is malware, so it should be assumed that it is malware.
upvoted 2 times
...
UranusNeptune
11 months ago
The answer is B because on the practice test I chose C which it told me was incorrect. Instead it told me the answer is B. So the Answer to this question is B
upvoted 1 times
...
b0bby
1 year, 1 month ago
Order of operations C then B then A. Questions is where are you. My perspective we know that malware on the PC but not how it got on my answer is C. In real world I'd be Quarantining the machine right away even as I continuing investigating on how it was installed to protect my other machines and keeping it from spreading. This as what seems to be the consistency another bad poorly worded question.
upvoted 1 times
b0bby
1 year, 1 month ago
Sorry Order of operations is C then A then B.
upvoted 1 times
...
...
Pisces225
1 year, 4 months ago
Selected Answer: C
The questions says the filename is “URGENT PLEASE READ.txt - In active folder, .txt file titled urgent please read”. Just because there's a .txt extension in the middle of the file name doesn't make this a text file. If Windows Explorer settings are default then known file extension types, such as .exe, will not be displayed. The technician should start at step one by investigating and verifying symptoms before proceeding to quarantine if confirmed.
upvoted 2 times
...
Rizierr
1 year, 4 months ago
this question is phrased so weird. i dont understand what its saying
upvoted 2 times
354fcf1
9 months, 1 week ago
I can't read this either lol
upvoted 1 times
...
...
PraygeForPass
1 year, 8 months ago
This is an interesting one. I don't know if I'm thinking too hard, but .txt extensions cannot execute anything. Even if there is code inside of it. So when opening it, all you will see is text. Because of this I would just use B, to check if there's anything malicious on the machine. If I'm not thinking hard and they are expecting a typical step, I would pick A, quarantine.
upvoted 2 times
...
dcv1337
1 year, 9 months ago
Selected Answer: B
I believe it's B but A is the next best answer in my opinion.
upvoted 2 times
...
Dadadagreat
1 year, 9 months ago
I would for letter A (Quarantine)
upvoted 2 times
...
mr_reyes
1 year, 11 months ago
Why wouldn't you ALWAYS quarantine the system before doing any other step? To prevent a possible spread.
upvoted 3 times
idoit
1 year, 11 months ago
The answer is phrased strangely. It says quarantine the host, which is normal, but it says "in the antivirus system" which is odd and I am not even sure what it means. You would normally quarantine it from the network.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago