Question

Difficulty: MediumMalware Symptoms and Standard Removal Procedures

An IT support technician at a maritime shipping terminal is troubleshooting a Windows 11 workstation used for cargo container tracking. The workstation was isolated from the local network after exhibiting unauthorized background network connections and browser redirects. The technician has already disabled System Restore on the machine to prevent infected restoration files. Which of the following actions should the technician perform NEXT according to the standard CompTIA 7-step malware removal procedure?

  1. Update the anti-malware definitions and software engine using a clean external media source.Answer
  2. B
    Re-enable System Restore and manually create a new system restoration point.
  3. C
    Schedule recurring daily anti-malware scans and Windows OS updates.
  4. D
    Provide cybersecurity awareness training to the terminal staff regarding safe browsing practices.

Answer

Update the anti-malware definitions and software engine using a clean external media source.
Following the CompTIA 7-step malware removal process (1. Identify, 2. Isolate, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore, 7. Educate end user), the immediate next step after disabling System Restore is Step 4: Remediate infected systems. Remediation begins by updating anti-malware definitions and engine software (Step 4a) prior to scanning and executing removal techniques (Step 4b). Because the workstation is isolated from the network, transferring updated definitions via clean external media is the correct procedural action.

Step-by-Step Solution

1
Identify the current step in the CompTIA 7-step malware removal framework.
The scenario confirms Step 1 (Identify symptoms), Step 2 (Isolate system), and Step 3 (Disable System Restore) have been completed.
Disabling System Restore ensures malicious files are not backed up or restored.
2
Determine the mandatory next action in the remediation sequence (Step 4).
Step 4 is 'Remediate infected systems', which begins with Step 4a: Update anti-malware definitions/software before scanning.
Scans are ineffective if conducted using outdated detection signatures.
3
Select the option representing Step 4a.
Updating anti-malware definitions via clean offline media directly matches Step 4a.
Since the machine is isolated from the network, definitions must be updated via clean external media or a controlled isolated source.

Key Concept

CompTIA 7-Step Malware Removal Procedure
Estimated Time:1m 0s
Rate this question