Question

Difficulty: MediumMalware Detection, Removal, and Prevention

A desktop technician at a municipal water treatment facility is remediating a Windows 11 workstation used for SCADA oversight that has been infected with persistent adware and unauthorized browser redirects. The technician has already verified the malware symptoms and quarantined the computer from the network. According to the standard CompTIA 7-step malware remediation workflow, which TWO of the following actions should the technician perform NEXT prior to running a full anti-malware scan?

  1. Disable System Restore in Windows configuration settings.Answer
  2. Update the anti-malware signature definitions and scanning engine.Answer
  3. C
    Enable System Restore and generate a new restore point.
  4. D
    Conduct end-user training on safe web browsing and browser security practices.

Answer

The technician should disable System Restore in Windows settings and update the anti-malware signature definitions.
Following quarantine (Step 2), the technician must proceed sequentially to Step 3 (Disable System Restore) and Step 4a (Update anti-malware definitions). Disabling restore points ensures malware cannot hide within volume shadow copies, and updating definitions ensures the anti-malware engine can recognize the specific adware and browser hijacking components during the subsequent scan.

Step-by-Step Solution

1
Identify current progress in the CompTIA 7-step malware remediation procedure.
Step 1 (Identify malware symptoms) and Step 2 (Quarantine infected systems) have already been completed.
Determining the current phase establishes what immediate remediation actions are required.
2
Select Step 3 of the malware remediation procedure.
System Restore must be disabled.
Disabling System Restore prevents clean restore points from being contaminated and prevents infected restore points from reinfecting the system.
3
Select Step 4a of the remediation process before running the scan.
Update the anti-malware software and definition files.
Up-to-date signature files ensure maximum threat detection coverage during the subsequent full system scan (Step 4b).

Key Concept

CompTIA 7-Step Malware Remediation Best Practices
Estimated Time:1m 30s
Rate this question