Question

Difficulty: MediumMalware Symptoms and Standard Removal Procedures

An IT support specialist at a regional transit authority is troubleshooting a Windows 11 workstation used for schedule dispatching. The computer exhibits active malware symptoms, including unexpected browser pop-ups and unusual background network traffic. The technician has confirmed the presence of malware and has already disconnected the network cable and disabled Wi-Fi to isolate the system. According to standard CompTIA 7-step malware remediation procedures, which of the following steps should the technician take NEXT?

  1. Disable System Restore in Windows.Answer
  2. B
    Boot into Safe Mode and run a full anti-malware scan.
  3. C
    Create a new System Restore point to save the current system state.
  4. D
    Replace the system storage drive due to suspected physical disk failure.

Answer

The technician should disable System Restore in Windows before proceeding to remediation.
According to the official CompTIA 7-step malware removal process (1. Identify, 2. Isolate, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore/create restore point, 7. Educate end user), the immediate step after isolating the system is to disable System Restore in Windows. This prevents Windows from taking automatic snapshots that include infected files or malware registry keys.

Step-by-Step Solution

1
Review the current step completed in the CompTIA 7-step malware removal process.
Step 1 (Identify symptoms) and Step 2 (Isolate infected system) have already been completed.
The scenario specifies that malware symptoms were verified and the workstation was disconnected from wired and wireless networks.
2
Determine the mandatory next step in the process sequence.
Step 3 is to disable System Restore in Windows.
Disabling System Restore purges existing restore points and prevents infected files from being saved during the clean-up phase.

Key Concept

CompTIA 7-Step Malware Removal Procedure
Rate this question