A systems administrator at a biotechnology research laboratory isolates an infected Windows 11 workstation from the local network and disables System Restore after observing unauthorized background data transmission and security alerts. The administrator then updates the anti-malware definitions and successfully removes all identified malicious software using a custom bootable scanner. According to CompTIA's standard 7-step malware removal procedures, what is the IMMEDIATE next step the administrator should take?
- Schedule recurring anti-malware scans and verify that operating system updates are configured.Answer
- BRe-enable System Restore and manually generate a clean restore point for the operating system.
- CReconnect the workstation to the laboratory network to confirm that normal network communication is restored.
- DConduct security awareness training with the primary user to prevent future social engineering compromises.
Answer
Schedule recurring anti-malware scans and verify that operating system updates are configured.
The correct answer represents Step 5 of the CompTIA 7-step malware removal process (Schedule scans and run updates). Once malware is successfully removed during the remediation phase (Step 4), the technician must set up automated recurring scans and ensure the OS and security software receive the latest updates to prevent re-infection.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Process Order