An IT support technician at a hospitality management company is troubleshooting a Windows 11 front-desk workstation that is displaying unauthorized security warnings and redirecting web browser traffic to malicious domains. The technician confirms that active rogue security software is present on the system. According to the CompTIA standard 7-step malware remediation process, which of the following actions should the technician take NEXT?
- Quarantine the infected workstation by disconnecting its network cable and disabling wireless interfaces.Answer
- BDisable Windows System Restore to prevent malware files from being saved in restore points.
- COpen Task Manager and Event Viewer to identify and terminate active malicious background processes.
- DUpdate the anti-malware software definitions and perform a full system scan in Safe Mode.
Answer
Quarantine the infected workstation by disconnecting its network cable and disabling wireless interfaces.
After identifying malware symptoms (Step 1), the immediate next action required by the standard CompTIA 7-step malware remediation process is to quarantine the infected host (Step 2). Disconnecting Ethernet cables and disabling Wi-Fi prevents lateral infection of other network assets and stops active malware from exfiltrating data or receiving remote commands.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Remediation Process - System Isolation / Quarantine
Estimated Time:1m 15s