A workstation operating in a clinical laboratory was disconnected from the network after exhibiting persistent rogue browser redirects and unauthorized background network traffic. The technician has confirmed the malware infection and completed the isolation step. According to standard CompTIA malware removal procedures, which of the following actions should the technician perform prior to running a full anti-malware system scan? (Select TWO.)
- Disable System Restore in Windows System PropertiesAnswer
- Update the anti-malware definition files and scanning engineAnswer
- CEnable System Restore and generate an immediate fresh system restore point
- DProvide end-user security awareness training regarding suspicious link clicks
Answer
The technician must disable System Restore and update the anti-malware definition files prior to initiating the full system scan.
According to CompTIA's 7-step malware removal process, after identifying the malware (Step 1) and isolating the system (Step 2), the technician must disable System Restore (Step 3). This prevents Windows from capturing infected files in restore points. Then, as part of remediation (Step 4), the technician must update the anti-malware signatures (Step 4a) prior to initiating the scan and removal phase (Step 4b).
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Procedure