nerdexam
Exams220-802Questions#631
CompTIA

220-802 · Question #631

220-802 Question #631: Real Exam Question with Answer & Explanation

The correct answer is C: Run the malware scan in Windows safe mode.. Some malware is persistent because it actively runs in the background during a normal Windows session, allowing it to re-infect files as the scanner removes them or to hide from the scanner. Safe mode loads only essential Windows drivers and services, preventing the malware from

Question

Anne, an end-user, reports to Joe, a helpdesk technician, that her computer has been redirecting her browser to unknown websites when clicking on search results. Joe runs a malware scan and finds that her computer is infected with malware. Joe uses the anti-malware program to remove the infection but Anne reports that the problem resurfaced the next day. Joe runs the malware scan again and finds the same malware is still infecting Anne's computer. Joe runs several passes of the malware scan to remove the infection but it keeps recurring. Which of the following would MOST likely aid in removing the infection?

Options

  • AEnable Windows User Access Control to ensure the user has proper rights to remove the infected files.
  • BDisable Windows firewall as it may be conflicting with the malware scan.
  • CRun the malware scan in Windows safe mode.
  • DChange the desktop's IP address to a different subnet.

Explanation

Some malware is persistent because it actively runs in the background during a normal Windows session, allowing it to re-infect files as the scanner removes them or to hide from the scanner. Safe mode loads only essential Windows drivers and services, preventing the malware from loading and actively running. This allows the anti-malware tool to fully detect and remove all components of the infection without interference. Enabling UAC or changing the IP address has no effect on resident malware. Disabling the firewall would make the system less secure and is never a recommended remediation step.

Community Discussion

No community discussion yet for this question.

Full 220-802 Practice