A desktop support analyst at a commercial aviation maintenance facility is troubleshooting a standalone workstation used to view engine schematics. The workstation is exhibiting classic malware symptoms, including high CPU usage, unauthorized process activity, and rogue security alerts. The analyst has already disconnected the machine from the network to isolate it and disabled System Restore in Windows. Which of the following actions should the analyst perform NEXT according to standard CompTIA malware removal procedures?
- Update malware definitions using a clean offline installation media and perform a full system scan.Answer
- BReconnect the workstation to the local network to download the newest anti-malware definition updates directly.
- CCreate a new system restore point to capture the current system configuration state prior to running removal tools.
- DSchedule recurring anti-malware scans and configure operating system updates.
Answer
Update malware definitions using a clean offline installation media and perform a full system scan.
Following the standard 7-step remediation framework (1. Identify, 2. Isolate, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore, 7. Educate user), after disabling System Restore, the immediate next action is Step 4: Remediate infected systems. Because the system is isolated, updating definition files offline via clean media and initiating a full scan fulfills Step 4.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Remediation Process Order