A helpdesk technician verifies that a corporate desktop is actively infected with malware that is attempting to communicate with an external command-and-control server. According to the CompTIA standard malware removal procedure, which of the following actions should the technician perform NEXT?
- Quarantine the infected system by disconnecting it from the network.Answer
- BDisable System Restore in Windows to clear existing restore points.
- CRun a full anti-malware scan to clean infected files.
- DEducate the end user on proper email attachment safety.
Answer
Quarantine the infected system by disconnecting it from the network.
According to the official CompTIA 7-step malware removal process, after verifying malware symptoms (Step 1), the immediate next step is to isolate/quarantine the infected system (Step 2). Disconnecting the system from the corporate network prevents the malware from propagating or communicating with malicious servers.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Procedure (Step 2: Quarantine/Isolate)