A cybersecurity technician is dispatched to address a suspected malware outbreak on several Windows workstations controlling automated sorting equipment in a pharmaceutical distribution center. The systems are exhibiting severe performance degradation, unusual background network traffic, and rogue process executions. To strictly adhere to the standard CompTIA 7-step malware removal procedure, which of the following preliminary steps MUST be completed before executing anti-malware remediation scans on these systems? (Select TWO.)
- Disconnect all physical network cables and disable wireless adapters on the infected workstations.Answer
- Disable System Protection on the Windows operating system to prevent malicious files from being saved in restore points.Answer
- CImmediately generate a fresh System Restore point to capture the operating system state before performing removal procedures.
- DExecute an immediate full anti-malware system scan while maintaining active network connectivity for real-time cloud definitions.
Answer
The technician must isolate the infected workstations from the network by disconnecting network interfaces and disable System Protection (System Restore) prior to running anti-malware remediation scans.
According to the official CompTIA 7-step malware remediation process, once symptoms are identified (Step 1), the technician must immediately isolate infected systems (Step 2) by disconnecting network interfaces. Following isolation, System Restore/System Protection must be disabled (Step 3) to clear existing restore points containing infected files before moving to remediation (Step 4). Therefore, isolating network connections and disabling System Protection are the two essential preliminary steps.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Procedure (Isolation & System Restore Disabling)