Question

Difficulty: EasyMalware Symptoms and Standard Removal Procedures

A helpdesk technician confirms that a Windows workstation is infected with malware and immediately unplugs its Ethernet cable to isolate the device from the network. According to CompTIA standard malware removal procedures, which of the following actions should the technician perform NEXT before running anti-malware removal tools?

  1. Disable System Restore in WindowsAnswer
  2. B
    Enable System Restore and create a new system restore point
  3. C
    Educate the end user on recognizing security threats
  4. D
    Reconnect the workstation to the local network to download updated anti-malware definitions

Answer

Disable System Restore in Windows
Following the mandatory CompTIA 7-step malware remediation process (1. Identify, 2. Isolate, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore, 7. Educate end user), after isolating the system, the technician must immediately disable System Restore. Disabling System Restore deletes existing restore points so infected files saved within those points cannot reinfect the machine later.

Step-by-Step Solution

1
Identify malware symptoms
Malware presence confirmed on the workstation.
Establishes that remediation procedures are necessary.
2
Isolate the infected system
Workstation disconnected from the network via physical Ethernet cable removal.
Prevents the infected machine from communicating with command-and-control servers or spreading laterally across the network.
3
Disable System Restore
System Protection turned off and existing restore points cleared.
Ensures that malware files are not backed up or preserved in Windows restore points during scanning and remediation.

Key Concept

CompTIA 7-Step Malware Removal Process Order
Estimated Time:45s
Rate this question