Question

Difficulty: MediumMalware Symptoms and Standard Removal Procedures

A financial analyst at a credit union reports that their Windows 11 workstation is displaying unexpected pop-up notifications and security warnings. An IT technician confirms the system has active malware and immediately disconnects the Ethernet cable and disables the Wi-Fi adapter to quarantine the device. According to the standard CompTIA 7-step malware removal procedure, which of the following actions should the technician perform NEXT?

  1. Disable Windows System Restore on the infected machine.Answer
  2. B
    Boot the computer into Safe Mode and run a full anti-malware scan.
  3. C
    Create a new manual restore point to save current configuration settings.
  4. D
    Schedule automatic weekly anti-malware scans and enable Windows Update.

Answer

Disable Windows System Restore on the infected machine.
According to the official CompTIA 7-step malware remediation procedure, once the malware symptoms are identified (Step 1) and the system is isolated from the network (Step 2), the immediate next step is to disable System Restore (Step 3). Disabling System Restore deletes previous restore points and prevents Windows from taking snapshots that contain infected files during the removal process.

Step-by-Step Solution

1
Identify symptoms and confirm malware infection
The technician confirmed active malware presence based on pop-up warnings.
Step 1 of CompTIA's 7-step process is identifying malware symptoms.
2
Isolate the infected system
The technician disconnected network cables and disabled Wi-Fi.
Step 2 isolates the system to prevent network propagation.
3
Disable System Restore
System Restore protection is turned off and existing restore points are cleared.
Step 3 prevents malware from persisting within restore points or being saved during cleanup.

Key Concept

CompTIA 7-Step Malware Removal Process
Estimated Time:1m 15s
Rate this question