A desktop support technician at a game development studio is responding to a workstation infected with spyware. The technician has successfully isolated the system from the network, disabled System Restore, updated the anti-malware definitions in Safe Mode, and executed a full scan that detected and removed all malicious files. Which of the following actions should the technician perform NEXT according to the standard CompTIA malware remediation process?
- Schedule recurring automatic anti-malware updates and system scans.Answer
- BRe-enable System Restore and create a fresh system restore point.
- CConduct end-user security awareness training regarding phishing and rogue downloads.
- DExecute the sfc /scannow command using System Configuration utility (msconfig).
Answer
Schedule recurring automatic anti-malware updates and system scans.
The CompTIA 7-step malware remediation process follows a strict sequential order: 1. Identify malware symptoms, 2. Quarantine infected systems, 3. Disable System Restore, 4. Remediate infected systems (update anti-malware, scan/remove), 5. Schedule updates and scans, 6. Enable System Restore and create a restore point, 7. Educate the end user. Since Step 4 has just been completed, the technician must proceed to Step 5 by scheduling recurring automatic updates and scans.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Remediation Process Order