A tier-2 helpdesk technician receives an escalated ticket regarding a workstation in a healthcare facility's radiology department. The workstation is experiencing extreme processing latency, rogue pop-up notifications, and unauthorized changes to browser settings. After confirming that these symptoms indicate an active malware infection, which of the following actions should the technician take NEXT prior to scanning and removing the malicious files? (Select TWO.)
- Disconnect the workstation from the local network by unplugging the Ethernet cable and disabling wireless connectionsAnswer
- Turn off Windows System Protection to disable System Restore points on the affected systemAnswer
- CCreate an immediate system restore point to safeguard existing registry settings
- DConduct an end-user training session on identifying phishing emails and malicious links
- EReplace the internal storage drive under the assumption of mechanical hardware failure
Answer
The technician should isolate the workstation from the network (unplug Ethernet and turn off Wi-Fi) and disable Windows System Restore.
According to the official CompTIA 7-step malware remediation process, after identifying the malware symptoms (Step 1), the immediate next steps are to isolate the infected system (Step 2) by severing wired/wireless network connections, and to disable System Restore (Step 3) so that malware files are not preserved in restore snapshots during remediation.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Procedure (Step 2: Isolate infected system, Step 3: Disable System Restore)
Estimated Time:2m 0s