Question

Difficulty: MediumMalware Symptoms and Standard Removal Procedures

A IT support specialist at a municipal utility district is responding to a Windows 11 desktop computer that exhibits symptoms of a malware infection. The technician has confirmed the presence of malicious processes and has completely isolated the workstation from the network by disconnecting the Ethernet cable and disabling all wireless radios. Following CompTIA's standard 7-step malware removal procedure, which of the following actions should the technician take NEXT?

  1. Disable Windows System Restore on the infected workstation.Answer
  2. B
    Re-enable System Restore and generate a fresh restore point immediately.
  3. C
    Replace the motherboard network interface card to resolve suspected packet loss.
  4. D
    Conduct end-user cybersecurity training on recognizing phishing links.

Answer

The technician should disable Windows System Restore on the infected workstation.
In CompTIA's standard 7-step malware remediation process, Step 3 requires disabling System Restore immediately after isolating the infected system (Step 2). Disabling System Restore deletes existing restore points, ensuring that infected copies of files cannot persist or be restored later.

Step-by-Step Solution

1
Identify the current step completed in the CompTIA 7-step malware removal process.
Step 1 (Identify malware symptoms) and Step 2 (Isolate infected systems) have already been completed.
The scenario explicitly states symptoms were identified and the machine was isolated from Ethernet/Wi-Fi.
2
Determine the mandatory next step in the standard sequence.
Step 3 is to disable System Restore.
Disabling System Restore prevents infected files from being saved into restore points or restored unintentionally during cleanup.

Key Concept

CompTIA 7-Step Malware Removal Procedure
Estimated Time:1m 0s
Rate this question