exam questions

Exam 220-1002 All Questions

View all questions & answers for the 220-1002 exam

Exam 220-1002 topic 1 question 131 discussion

Actual exam question from CompTIA's 220-1002
Question #: 131
Topic #: 1
[All 220-1002 Questions]

A technician is attempting to repair a Windows computer that is infected with malware. The machine is quarantined but still cannot boot into a standard desktop.
Which of the following is the most likely NEXT step?

  • A. Disable System Restore.
  • B. Create a restore point.
  • C. Apply system updates.
  • D. Restart into safe mode.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Zathereth
Highly Voted 4 years, 11 months ago
Technically you should disable system restore, but since the question specifies that the computer can't enter into standard desktop, it is probably best to go with safe mode.
upvoted 14 times
kyogen
4 years, 9 months ago
Agreed.
upvoted 2 times
...
...
Tech1990
Most Recent 2 years, 7 months ago
Selected Answer: D
It should be D only.
upvoted 1 times
...
Rockm0uld
2 years, 8 months ago
Selected Answer: A
Come on, you should know this by now! "The 1002 exam outlines the following multistep process as the best practice procedures for malware removal: 1. Identify and research malware symptoms. 2. Quarantine the infected systems. 3. Disable System Restore (in Windows). 4. Remediate the infected systems. A. Update the anti-malware software. B. Scan and use removal techniques (Safe Mode, Preinstallation Environment). 5. Schedule scans and run updates. 6. Enable System Restore and create a restore point (in Windows). 7. Educate the end user." Taken from Mike Meyers' book
upvoted 1 times
aurelien123
2 years, 8 months ago
you couldn't disable the system restore if you were not able to boot your system, "you should know this by now" =p
upvoted 9 times
...
...
Hundo_954
2 years, 10 months ago
A. Disable system restore. You can disable system restore without the standard desktop. In Mike Meyers video, he goes into the Windows Recovery Environment > Troubleshoot > then there is an option for command prompt. You can disable System Restore from the command prompt by disabling its registry key
upvoted 1 times
...
iLikeBeagButt
3 years ago
Is it possible to disable system restore in Safe mode?
upvoted 1 times
...
[Removed]
3 years, 6 months ago
If windows safe mode not booting too, best bet is a windows PE bootup disk.
upvoted 1 times
...
rrizzo
4 years, 7 months ago
D is absolutely correct answer. Boot into safe mode if you cannot boot in standard mode. Try to scan for malware using malwarebytes - You cannot disable system restore without being able to boot it up so why would you choose A?
upvoted 4 times
Austin13215
3 years, 7 months ago
That makes sense, I agree with you.
upvoted 1 times
...
...
CobraBoy
4 years, 10 months ago
I guess, to do a system restore, you need to access your desktop and if that is not possible next best option would be to boot into safe mode and disable system restore.
upvoted 1 times
...
bohica
4 years, 11 months ago
so you have to be able to turn it on in order to disable system restore
upvoted 1 times
...
Javier25
5 years, 1 month ago
The machine is quarantined but still can't boot into a Standard Destop
upvoted 1 times
...
adrian1234
5 years, 1 month ago
Surely disable system restore is the next step after quarantine????
upvoted 4 times
mfombi
4 years, 10 months ago
How when the computer cant boot into desktop? You have to access the system restore in order for you to disable it.
upvoted 7 times
...
Anon6606
4 years, 7 months ago
but still cannot boot into a standard desktop.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago