CompTIA A+ Core 2 (220-1202)SecurityHard

A user installs a new browser extension advertised as a 'productivity booster'. Shortly after, they notice their browser's default search engine has changed, new toolbars appear, and they are constantly redirected to various shopping sites. The extension also seems to track their browsing history without explicit consent. Which browser security issue is most likely occurring?

  1. AMan-in-the-Browser (MitB)
  2. BCross-Site Scripting (XSS)
  3. CMalicious Extension/Add-on
  4. DBrowser Hijacking
Show answer & explanation

Correct answer: C. Malicious Extension/Add-on

While 'Browser Hijacking' is a symptom, the root cause is the 'Malicious Extension/Add-on' that the user installed. This extension is actively performing the hijacking, changing settings, injecting ads, and tracking data. MitB is a specific type of malware that intercepts browser traffic, and XSS is a web vulnerability, neither of which directly describes the installation of a malicious extension causing these effects.

Why the other options are wrong

  • A. MitB is a broader category of malware that hooks into the browser process to modify web pages or transactions, but the direct cause here is an installed extension, not necessarily a separate MitB malware.
  • B. XSS is a client-side code injection attack, not directly caused by an installed extension changing browser settings.
  • D. Browser Hijacking is the *effect* (browser settings changed, redirects), but the *cause* described is the malicious extension itself.

Malicious Browser Extension

A browser add-on or plugin that appears legitimate but is designed to perform harmful actions, such as changing browser settings, injecting advertisements, tracking user data, or redirecting traffic, often without the user's full knowledge or consent.

  • Installed by the user (often unknowingly)
  • Can alter browser settings (homepage, search engine)
  • Injects ads or redirects traffic
  • May track browsing history and personal data
  • Often disguised as 'productivity' or 'utility' tools

Memory trick: An extension can hijack your browser, but XSS is a script, not an install.

More Security questions