nerdexam
CompTIA

220-1002 · Question #601

A user is trying to access a popular email website but Is being redirected to a different website that asks for login credentials. The user calls a technician, who promptly notices a security issue…

The correct answer is B. Remove all files from the temporary folder and restart the computer. A user being redirected to a credential-harvesting site indicates malicious cached browser data, and clearing the temporary folder then restarting removes the threat causing the redirect.

Networking

Question

A user is trying to access a popular email website but Is being redirected to a different website that asks for login credentials. The user calls a technician, who promptly notices a security issue. Which of the following should the technician do to remove the threat from the system?

Options

  • ARemove all parameters after the FQDN website address
  • BRemove all files from the temporary folder and restart the computer.
  • CRemove and reinstall the web browser In safe mode.
  • DRemove all lines that are not comments from the hosts file

How the community answered

(50 responses)
  • A
    8% (4)
  • B
    76% (38)
  • C
    14% (7)
  • D
    2% (1)

Why each option

A user being redirected to a credential-harvesting site indicates malicious cached browser data, and clearing the temporary folder then restarting removes the threat causing the redirect.

ARemove all parameters after the FQDN website address

Removing URL parameters from the address bar does not address any underlying malicious files or system configuration changes causing the redirect.

BRemove all files from the temporary folder and restart the computer.Correct

Malicious files or scripts stored in the browser's temporary folder can persistently redirect users to phishing sites designed to steal credentials. Deleting all files from the temporary folder removes the cached malicious content, and restarting the computer terminates any active processes that were leveraging it to perform the redirect, restoring normal browsing behavior.

CRemove and reinstall the web browser In safe mode.

Reinstalling the browser in safe mode is more involved than necessary and does not guarantee removal of malicious files that persist in the temporary folder outside the browser's installation directory.

DRemove all lines that are not comments from the hosts file

Clearing non-comment lines from the hosts file would remediate a hosts-file-based DNS redirect but does not address browser-cached malicious content stored in temporary files.

Concept tested: Removing browser redirect malware via temporary file cleanup

Source: https://support.microsoft.com/en-us/windows/delete-temporary-files-in-windows-a082b9b8-1c32-48b7-a9e0-9a4c52a3d7b6

Topics

#browser redirect#hosts file hijack#malware removal#phishing

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice