Question

Difficulty: HardMalware Symptoms and Standard Removal Procedures

A tier-2 helpdesk technician receives an escalated ticket regarding a workstation in a healthcare facility's radiology department. The workstation is experiencing extreme processing latency, rogue pop-up notifications, and unauthorized changes to browser settings. After confirming that these symptoms indicate an active malware infection, which of the following actions should the technician take NEXT prior to scanning and removing the malicious files? (Select TWO.)

  1. Disconnect the workstation from the local network by unplugging the Ethernet cable and disabling wireless connectionsAnswer
  2. Turn off Windows System Protection to disable System Restore points on the affected systemAnswer
  3. C
    Create an immediate system restore point to safeguard existing registry settings
  4. D
    Conduct an end-user training session on identifying phishing emails and malicious links
  5. E
    Replace the internal storage drive under the assumption of mechanical hardware failure

Answer

The technician should isolate the workstation from the network (unplug Ethernet and turn off Wi-Fi) and disable Windows System Restore.
According to the official CompTIA 7-step malware remediation process, after identifying the malware symptoms (Step 1), the immediate next steps are to isolate the infected system (Step 2) by severing wired/wireless network connections, and to disable System Restore (Step 3) so that malware files are not preserved in restore snapshots during remediation.

Step-by-Step Solution

1
Identify malware symptoms
Confirmed malware infection based on extreme processing latency, pop-ups, and browser redirects.
Completes Step 1 of the CompTIA 7-step malware removal process.
2
Isolate the infected system
Physical and wireless network connections are severed.
Prevents lateral movement of malware across the healthcare network and stops exfiltration of sensitive patient data.
3
Disable System Restore
System Protection is turned off, purging/suspending infected restore points.
Ensures that malware binaries stored in existing restore snapshots cannot survive or be restored post-cleanup.

Key Concept

CompTIA 7-Step Malware Removal Procedure (Step 2: Isolate infected system, Step 3: Disable System Restore)
Estimated Time:2m 0s
Rate this question