Free Common Personal Computer (PC) Security Issues practice questions
10 free 220-1202 questions on Common Personal Computer (PC) Security Issues, each with a full explanation — no account needed. This section sits in the Software Troubleshooting part of the exam. Answer every question to see your score, then read the lessons below for anything you missed.
A user with an iPhone reports that a particular app crashes repeatedly. Following best practices, which action should a technician attempt FIRST before escalating to more disruptive steps?
The best troubleshooting approach on iOS is to start with the least disruptive step and escalate only if needed. Force closing the app and reopening it clears the app's stuck state without affecting any user data or system settings, making it the correct first action for a repeatedly crashing app. If that fails, the technician might reboot the device, then update iOS and the app, and finally consider reinstalling. Performing a factory reset wipes all user data and returns the device to default settings; this is far too drastic for a single misbehaving app and should be reserved for severe issues or resale preparation. Resetting all network settings addresses Wi-Fi, Bluetooth, and cellular connectivity problems, not application crashes, so it targets the wrong subsystem. Restoring from an iCloud backup is a lengthy recovery operation that is unnecessary and disproportionate for a single crashing app. Following the least-to-most-disruptive methodology minimizes downtime and data risk while resolving the majority of common app problems quickly.
A remote employee reports that their laptop keeps failing to complete a large feature update, getting stuck partway through the download over their home Wi-Fi. Which two prerequisites should the technician verify FIRST?
Network stability and available disk space are the two prerequisites to verify first because feature updates require large downloads plus room for temporary files and rollback data, and flaky home Wi-Fi commonly interrupts the process and leaves updates half-installed. Confirming a stable connection and sufficient free space addresses the most likely causes of an update that stalls partway through a download. Screen resolution and installed browser version have no bearing on whether an OS update can download and install. Antivirus subscription and license key status do not typically cause a download to stall, although third-party antivirus can occasionally block installers, so that is not the first thing to check. The user account password and biometric settings relate to signing in, not to completing an update. The troubleshooting habit for failed updates is to check prerequisites such as power, disk, and network first, then review logs and update history, and finally plan a rollback if needed.
A user reports that their web browser keeps displaying full-screen pop-ups claiming 'Critical threat detected' with a countdown timer and a phone number to call for immediate support. The message cannot be confirmed anywhere in Windows Security. Which of the following BEST describes what the technician is observing?
A scareware pop-up is designed to create panic and rush the user into an action such as calling a number, paying money, or installing a 'cleaner' tool. Key indicators include a vague product identity, a fear-based countdown, a support phone number, and the fact that it cannot be confirmed inside Windows Security or the real vendor app. A legitimate antivirus quarantine notification names the product clearly and can be verified in Windows Security or the vendor application, and it never demands a phone call or payment. A Windows Update service failure alert appears through Windows itself and describes an update problem, not a threat requiring immediate payment or a call. A standard browser certificate warning indicates the browser cannot verify a site's identity and offers options to proceed or go back, without countdowns or support phone numbers. The rule to remember is that any alert demanding money, a phone call, or remote access should be treated as untrusted until proven otherwise. Real security tools suggest scans, updates, or quarantines and follow predictable behavior, while scareware relies on urgency and threats to bypass rational judgment.
A technician is troubleshooting a PC that cannot reach most websites, though a few sites still load. Other devices on the same Wi-Fi network browse normally, and security vendor websites specifically fail to load. Which of the following is the MOST likely cause?
Malware manipulating DNS or proxy settings commonly creates selective failures, where certain sites load while others fail. A strong red flag is that security vendor sites are specifically blocked, since malware often prevents antivirus updates while leaving normal browsing partly functional. Because other devices on the same Wi-Fi work correctly, the problem is local to the PC rather than the shared network. An ISP outage would affect every device on the network, not just the single PC, and would not selectively block security vendor sites. A malfunctioning router requiring a reboot would also impact other devices, and again would not target only security-related domains. A failed Windows feature update can break networking, but it typically causes a broader loss of connectivity rather than the pattern of security sites failing while other sites work. When one device can reach only some sites and specifically cannot reach security vendors, treat it as a security symptom first. The correct next steps include checking proxy settings, confirming DNS is provided by the router or a trusted provider, inspecting the hosts file for tampering, and running a trusted scan, ideally from an offline or clean environment where malware has less control.
A user's files across multiple folders have been renamed with an unfamiliar extension within minutes, several documents will not open, and text files titled with recovery instructions appear in each directory. The technician also notices sustained high disk activity. Which of the following should the technician do FIRST?
Disconnecting the PC from the network immediately is the correct first step when ransomware is suspected. Mass renaming with a new extension, documents that will not open, ransom note text files, and sustained high disk activity are classic ransomware indicators. Isolating the device by turning off Wi-Fi or unplugging Ethernet limits spread to network shares and slows further encryption. Paying the ransom is never appropriate as an A+ response because payment does not guarantee recovery, can violate policy, and may fund further criminal activity. Running Disk Cleanup to remove the ransom notes destroys evidence needed for investigation and does nothing to recover the encrypted data. Renaming the affected files to their original extensions does not decrypt them, since encryption changes the file contents, not just the name, and this action wastes time while the process may still be running. The proper containment sequence is to isolate the device, avoid paying, report the incident to the appropriate person, preserve evidence such as screenshots and the extension pattern, and verify that backups are not also encrypted. If cleanup cannot be confirmed, the device may need to be re-imaged and restored from verified backups.
A technician suspects a PC is compromised and wants to change the user's passwords to prevent account takeover. Which of the following is the BEST practice for changing the passwords?
Changing the passwords from a separate clean device is the best practice when a PC may be compromised. If the device is infected with malware such as a keylogger, typing new passwords on that machine could immediately expose the new credentials to the attacker. Email accounts should be prioritized first because email is used to reset most other passwords, and enabling multi-factor authentication further reduces harm even if a password leaks. Changing the passwords from the possibly infected PC defeats the purpose, since the compromised system could capture the new passwords as they are entered. Changing the passwords after reinstalling the OS delays protection unnecessarily; credentials may already be actively stolen and misused, so waiting increases the window of exposure. Changing the passwords only after removing all malware also leaves accounts vulnerable during the cleanup period, which can take significant time and may not fully succeed. The guiding principle is to protect people and accounts first, then the device. Using a known-clean phone or a different PC ensures the reset credentials never pass through the potentially compromised system, breaking the attacker's access as quickly as possible.
A user reports desktop pop-up alerts appearing even when they believe the browser is fully closed. The technician confirms the alerts come from a website the user previously clicked 'Allow' on. Which of the following is the MOST appropriate fix?
Removing the site from the browser's notification permissions is the correct fix because these desktop alerts are browser push notifications, not Windows alerts or malware. When a user clicks 'Allow' on a site's notification prompt, the site can send spam to the desktop at any time. Browsers such as Chrome, Edge, and Firefox can run in the background, so the alerts appear even when the browser looks closed. The fix is to open the browser's notification settings and remove or block the offending site. Reinstalling the operating system is a drastic, unnecessary measure for a simple browser permission issue and would cause needless disruption and data loss risk. Disabling the Windows Security notification service is incorrect because the alerts do not originate from Windows Security, and turning off that service would weaken legitimate security notifications. Running an offline antivirus scan targets malware, but browser push notification abuse is a permission problem, not an infection, so the scan would not address the granted permission. The lasting solution also includes reviewing extensions for adware and, if the user repeatedly clicks Allow by mistake, setting the browser to block new notification requests entirely.
A user receives a certificate warning on a banking website. The technician notes the system clock displays the wrong date. Which of the following should the technician check or correct FIRST?
Correcting the system date, time, and time zone should be done first because certificate validation depends heavily on accurate system time. If the clock is wrong, certificates can appear expired or not yet valid, triggering warnings on otherwise legitimate sites. Fixing the time often clears the warning immediately, and it is the simplest, lowest-risk explanation to test. Reinstalling the browser to restore trusted root certificates is a heavier step that is unnecessary when the obvious cause is an incorrect clock; it should only be considered after simpler checks fail. Adding an exception to bypass the certificate warning is dangerous because it trains users to ignore the one alert designed to stop credential theft, and it should never be done on a login or payment page. Disabling TLS certificate validation in the browser removes essential protection against interception and man-in-the-middle attacks, exposing all connections to snooping and tampering. The proper sequence for certificate warnings is to check the clock, update the browser and OS, clear SSL state, and test on another network before assuming hostile conditions. Only after simple causes are ruled out should the warning be treated as a possible interception event.
A technician is investigating a PC that redirects searches through an unknown engine and displays injected ads on reputable websites. The technician wants to determine whether the problem is limited to one browser or affects the entire system. Which of the following tests is BEST?
Testing the same site in a different browser on the PC is the best isolation step because it quickly reveals whether the symptom is tied to one browser profile or is system-wide. If only one browser redirects, the cause is likely an extension, corrupted settings, or a damaged profile in that browser. If all browsers on the PC are affected, the cause is more likely a system-wide proxy, a malicious hosts file entry, a hostile root certificate, or malware. Clearing all browsing history and cookies immediately can erase valuable clues before the source is identified, and it does not distinguish between browser-level and system-level causes. Resetting the router to factory default settings is premature and disruptive; it should only be considered if the problem is shown to follow the network, which requires isolation testing first. Uninstalling and reinstalling the affected browser is a fix attempt, not a diagnostic test, and if the cause is system-wide malware, the symptom will simply return in the reinstalled browser. The principle is to isolate the layer first, browser, system, or network, before choosing the least disruptive fix, which reduces the chance of repeated reinfection and wasted effort.
A user reports that their essays and notes now show modified timestamps from times the PC was asleep, and a few documents open with extra pages and unfamiliar hyperlinks. Earlier that day, the user installed a 'free PDF tool' from an unknown website. Which of the following symptom patterns does this MOST likely represent?
Altered files resulting from unauthorized access is the most likely pattern because the combination of unexpected software installation plus unexplained file changes is a classic security symptom. Timestamps that do not match the user's work pattern, such as edits during hours the PC was asleep, along with content changes like extra pages and unfamiliar hyperlinks, point to tampering rather than routine activity. The recent installation of a 'free PDF tool' from an unknown site strongly suggests a bundled threat. Normal auto-save and background indexing behavior would not change document content or add hyperlinks, and it would not produce edits at times the PC was inactive. A cloud sync conflict creating duplicate copies produces '(1)' style filenames and merge artifacts, not altered content with new pages and links inside existing documents. A failing hard drive corrupting stored documents typically causes read/write errors, files that will not open, or garbled data, rather than coherent modifications like added pages and functional hyperlinks. A single strange file can be a mistake, but a cluster of unexplained changes in the same window, especially following suspicious software, should be treated as suspicious. The proper triage is to disconnect networking, review Protection history and recent installs, check startup apps, and compare file version history before attempting any repair.
Study this section
Every lesson that covers Common Personal Computer (PC) Security Issues on the 220-1202 exam.