A systems administrator has successfully remediated a malware infection on a workstation, updated the anti-malware software signatures, and scheduled recurring system scans. According to standard CompTIA malware removal procedures, which of the following steps should the administrator take NEXT?
- Enable System Restore and create a new restore pointAnswer
- BEducate the end user on safe browsing habits and security awareness
- CIsolate the computer by disconnecting its network interface card
- DRe-disable System Restore to prevent future infected restore points
Answer
Enable System Restore and create a new restore point.
Under the standard 7-step malware removal process (1. Identify, 2. Isolate, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore and create restore point, 7. Educate end user), re-enabling System Restore and creating a fresh restore point immediately follows scheduling scans and updates.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Procedure - Step 6 (Enable System Restore and create a restore point)