Question

Difficulty: EasyMalware Symptoms and Standard Removal Procedures

A desktop technician confirms that a Windows 11 workstation in a corporate office is infected with rogue anti-spyware software. The technician has already disconnected the network cable to isolate the system from the corporate network. According to the standard CompTIA 7-step malware removal procedure, which action should the technician take NEXT?

  1. Disable System Restore in Windows.Answer
  2. B
    Run a full system anti-malware scan.
  3. C
    Create a new System Restore point.
  4. D
    Educate the user on safe web browsing practices.

Answer

Disable System Restore in Windows.
The standard CompTIA 7-step malware removal process follows a specific order: 1) Identify symptoms, 2) Isolate infected systems, 3) Disable System Restore, 4) Remediate infected systems, 5) Schedule scans and updates, 6) Enable System Restore and create a restore point, 7) Educate end user. Because the system has already been identified and isolated, disabling System Restore is the required next step.

Step-by-Step Solution

1
Identify the current step in the CompTIA 7-step malware removal process.
The scenario describes Step 1 (Identify malware symptoms) and Step 2 (Isolate infected systems) as already completed.
The technician confirmed the infection and disconnected the network cable to isolate the system.
2
Determine the mandatory next step in sequence.
Step 3 is to disable System Restore.
Disabling System Restore deletes existing restore points so malicious files cannot be restored accidentally during or after remediation.

Key Concept

CompTIA 7-Step Malware Removal Procedure Sequence
Estimated Time:45s
Rate this question