exam questions

Exam 220-1102 All Questions

View all questions & answers for the 220-1102 exam

Exam 220-1102 topic 1 question 13 discussion

Actual exam question from CompTIA's 220-1102
Question #: 13
Topic #: 1
[All 220-1102 Questions]

A technician suspects a rootkit has been installed and needs to be removed. Which of the following would BEST resolve the issue?

  • A. Application updates
  • B. Anti-malware software
  • C. OS reinstallation
  • D. File restore
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Fuzm4n
Highly Voted 2 years, 6 months ago
Selected Answer: C
BEST way to remove it completely is to reinstall the OS
upvoted 21 times
...
Paula77
Highly Voted 1 year, 7 months ago
Selected Answer: B
Rootkits are a type of malware that embeds itself deeply into the operating system, making them difficult to detect and remove. Specialized anti-malware software, often referred to as "anti-rootkit" tools, are designed to detect and remove rootkits from a system. These tools are specifically engineered to identify and eliminate the hidden and malicious components of rootkits. While other measures like OS reinstallation or file restore might be necessary in severe cases, using anti-malware software is typically the first and most effective step to take when dealing with a suspected rootkit infection.
upvoted 7 times
willyww
10 months ago
please don´t comment no sense answers that confuse the comunnity, the answer is C "emekus" is right
upvoted 1 times
...
Emekus
1 year, 6 months ago
A rootkit embeds itself in the....wait for it.....root of the OS and it very likely to be undetected as the Antimalware runs after it has done its business. It takes control of the MBR/GPT so wahatever scans you run, isn't going to find it. ALWAYS the answer to rootkits is OS reinstalltion...ALWAYS. 23 years of dealing with rootkits here.
upvoted 11 times
...
...
jonrich505
Most Recent 5 days, 10 hours ago
Selected Answer: C
C. because reinstallation is a fresh start and can eliminate a rootkit because the drive will be wiped clean and goes back to factory settings.
upvoted 1 times
...
hawaiian_76
3 months, 2 weeks ago
Selected Answer: C
"BEST" resolve i believe is to reinstall the OS. that way theres no IF or Maybe its fixed, with the anti malware software
upvoted 1 times
...
gcody
5 months, 3 weeks ago
Anti-malware software_I say this is the first option before reinstalling an OS
upvoted 1 times
...
HeatSquad77
6 months, 3 weeks ago
Selected Answer: C
Anti malware software will not detect a rootkit therefore wont remove it. Reinstalling the OS will fix the issue
upvoted 2 times
...
dickchappy
7 months, 2 weeks ago
Selected Answer: C
Even assuming your anti-malware can somehow magically detect a rootkit (it won't, because it's a rootkit) the BEST solution to ensure it is not there anymore is a full reinstallation of the OS.
upvoted 1 times
...
Raffaelloo
7 months, 2 weeks ago
Selected Answer: C
A rootkit is software used by cybercriminals to gain control over a target computer or network. Rootkits can sometimes appear as a single piece of software but are often made up of a collection of tools that allow hackers administrator-level control over the target device
upvoted 2 times
...
ScorpionNet
7 months, 2 weeks ago
Selected Answer: C
Reinstalling the operating system will be more effective than the antivirus software because rootkits often bypass the antivirus scan making it difficult for the antivirus to remove it. To those that are getting into cybersecurity, these are referred as black hat hackers.
upvoted 5 times
...
Jay23AmMonsIV
7 months, 2 weeks ago
Selected Answer: C
Here's why this is the best approach: Thorough Removal: Rootkits are designed to hide their presence and can be extremely difficult to detect and remove. They often operate at a low level in the system, making them resistant to many traditional anti-malware tools. System Integrity: Reinstalling the operating system ensures that any rootkit, along with any other potential malware or system modifications, is completely removed. This restores the system to a known good state. Prevention of Future Issues: A clean OS reinstallation eliminates any potential backdoors or malicious code that a rootkit might have installed, providing a fresh start and reducing the risk of re-infection. While anti-malware software can be effective against many threats, rootkits are particularly insidious and may evade detection. Application updates and file restores do not address the root cause and may not be effective against rootkits. Therefore, an OS reinstallation is the most reliable method to ensure the rootkit is completely removed.
upvoted 2 times
...
SixGoddess
7 months, 2 weeks ago
Selected Answer: C
THE ANSWER IS C
upvoted 1 times
...
Philco
8 months ago
Selected Answer: C
Reinstall Windows If the rootkit is deeply embedded, you might need to reinstall Windows using a clean install from an external media.
upvoted 2 times
...
igorclapa
1 year, 1 month ago
Selected Answer: C
C. If you suspect a rootkit on your device, it's so over. You have to reinstall your OS.
upvoted 2 times
...
yutface
1 year, 2 months ago
Selected Answer: C
Anti malware programs do not get rid of rootkits. IT 101. Reinstall OS everytime. I do it at work all the time.
upvoted 1 times
...
simjay93
1 year, 2 months ago
a root kit should be removed by file restore ,the answer has to be D
upvoted 1 times
...
Chavozamiri
1 year, 5 months ago
Selected Answer: B
B. Anti-malware software I will go with this option because the question says SUSPECT so have a doubt and need make sure better install anti-malware to scan to make sure...
upvoted 2 times
...
mohdAj
1 year, 5 months ago
Selected Answer: C
The BEST resolves the issue is C - OS reinstallation
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago