Question

Difficulty: MediumMalware Symptoms and Standard Removal Procedures

An IT technician at a boutique hotel front desk is responding to a Windows 10 workstation that displays rogue pop-up messages and exhibits unprompted network traffic. The technician has confirmed malware symptoms and immediately disconnected the workstation from the Ethernet network and Wi-Fi. According to the CompTIA 7-step malware removal process, which of the following actions should the technician perform next?

  1. Disable System Restore in Windows.Answer
  2. B
    Update anti-malware signatures and perform a full system scan.
  3. C
    Replace the physical network interface card to resolve local network degradation.
  4. D
    Provide security awareness training to the hotel front desk staff.

Answer

Disable System Restore in Windows.
In the standard CompTIA 7-step malware removal procedure (1. Identify symptoms, 2. Isolate infected systems, 3. Disable System Restore, 4. Remediate infected systems, 5. Schedule scans and updates, 6. Enable System Restore and create restore point, 7. Educate end user), the technician has already completed steps 1 and 2. Therefore, the immediate next step is to disable System Restore so that infected files are not accidentally backed up or protected by system protection mechanisms.

Step-by-Step Solution

1
Identify current progress in the 7-step malware removal process
Step 1 (Identify malware symptoms) and Step 2 (Isolate infected systems) have already been completed by confirming symptoms and disconnecting network access.
Following the standardized CompTIA procedure ensures complete malware eradication without reinfection.
2
Determine the mandatory next step following system isolation
Step 3 is to disable System Restore in Windows.
Disabling System Restore purges existing restore points and prevents Windows from creating backup copies of active malware files during remediation.

Key Concept

CompTIA 7-Step Malware Removal Process
Rate this question