A receptionist at a medical clinic reports that a Windows workstation used for check-ins is displaying unexpected adware pop-ups and generating heavy unauthorized network traffic. A technician inspects the system and confirms an active malware infection. According to the CompTIA standard 7-step malware removal process, which of the following actions should the technician perform IMMEDIATELY after identifying the infection?
- ADisable System Restore in Windows settings
- Disconnect the workstation from the networkAnswer
- CPerform a full system scan using updated antivirus signatures
- DTrain the receptionist on identifying suspicious web links
Answer
Disconnect the workstation from the network
Following the CompTIA 7-step malware removal process (1. Identify symptoms, 2. Isolate infected system, 3. Disable System Restore, 4. Remediate infected system, 5. Schedule scans and updates, 6. Enable System Restore, 7. Educate end user), the immediate next step after identifying malware is to isolate the system by disconnecting it from wired or wireless networks.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Procedure (Step 2: Isolate infected systems)
Estimated Time:45s