220-1102 - Security (25% of the exam) - Section 2.3

Detect, remove, and prevent malware, and explain common social-engineering attacks, threats, and vulnerabilities.

Identify malware types - ransomware, trojan, keylogger, rootkit, virus, spyware, cryptominer - and the correct tools and removal steps, including recovery console, anti-malware, and software firewalls. Explain social-engineering attacks (phishing, vishing, shoulder surfing, tailgating, impersonation) and broader threats such as DoS, DDoS, on-path attacks, spoofing, and zero-day vulnerabilities, and recognise the best mitigation for each.

RansomwarePhishingRootkitZero-daySocial engineering

Practice question for this objective

Free sampleSecuritymedium

Which characteristic most distinguishes a rootkit from other categories of malware?

  • AIt encrypts the user's documents and then demands a ransom payment in exchange for the decryption key.
  • BIt requires the victim to open an infected email attachment before any of its code is able to execute.
  • CIt floods a target server with traffic from many sources to exhaust that server's available resources.
  • DIt obtains privileged access and conceals its own presence and other malware from the operating system and detection tools. Correct
Identify a rootkit by its use of privileged access to hide itself and other malware from the operating system and security tools. A rootkit's defining trait is stealth through privilege: by running at a high privilege level it intercepts and alters what the operating system reports, concealing its own components and any malware it protects from standard detection.

Why A is wrong: This is tempting because both are serious threats, but encrypting data for extortion describes ransomware; a rootkit's purpose is stealthy persistent access, not extortion.

Why B is wrong: This is tempting because many infections start with attachments, but that is a delivery method common to much malware, not the defining trait of a rootkit.

Why C is wrong: This is tempting as a well-known attack, but resource exhaustion by traffic describes a distributed denial-of-service attack, not a rootkit.

Why D is correct: Correct: a rootkit operates with elevated or kernel-level privilege and hides files, processes, and other malware from the OS and scanners, making it hard to detect and remove.

See more 220-1102 practice questions, answers explained.

Exam traps in Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the 220-1102 bank for this domain.

  • Boot from installation media and reinstall Windows to clear the recovery prompt.

    Why it is wrong: Tempting as a reset, but reinstalling destroys the user's data and is unnecessary because the volume is intact and only needs the recovery key to unlock.

  • Spyware, which covertly monitors user activity and gathers personal information or credentials without the victim's consent.

    Why it is wrong: Tempting because it is stealthy and harmful, but spyware secretly collects information rather than encrypting files and extorting a payment to restore them.

  • Update the anti-malware definitions and run a full scan to detect and remove the active infection immediately.

    Why it is wrong: Remediation is the following stage and is essential, but running it before disabling System Restore risks leaving an infected restore point behind, so it is premature.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.