A desktop support technician at a maritime shipping terminal is responding to a Windows workstation exhibiting active ransomware symptoms. Place the following CompTIA standard malware remediation actions in the correct order from first to last.
- 1Disconnect the workstation's network cable and disable wireless interfaces.
- 2Turn off Windows System Restore.
- 3Update anti-malware definitions and execute a complete remediation scan.
- 4Re-enable Windows System Restore and create a clean restore point.
- 5Provide security awareness guidance to the terminal operator on phishing prevention.
Answer
The correct order of steps is: 1. Disconnect the workstation's network cable and disable wireless interfaces. 2. Turn off Windows System Restore. 3. Update anti-malware definitions and execute a complete remediation scan. 4. Re-enable Windows System Restore and create a clean restore point. 5. Provide security awareness guidance to the terminal operator on phishing prevention.
According to CompTIA's 7-step malware removal procedure, the technician must first isolate the system from the network to stop lateral spread. Next, System Restore must be disabled so that infected files are not retained in system restore points. Once disabled, the technician updates anti-malware signatures and remediates the computer. After confirming remediation, System Restore is re-enabled and a new restore point is generated. Finally, educating the end user prevents recurrence.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Process
Estimated Time:1m 15s