Question

Difficulty: MediumMalware Symptoms and Standard Removal Procedures

A desktop technician at a commercial law firm is responding to a Windows workstation displaying unauthorized pop-up security warnings and browser redirects. The technician confirms active malware and immediately disconnects the Ethernet cable to isolate the system from the network. According to the CompTIA standard 7-step malware remediation procedure, which action should the technician take NEXT?

  1. Disable System Restore in Windows to prevent infection points from being backed up or re-infected.Answer
  2. B
    Update anti-malware signatures and perform a comprehensive system scan.
  3. C
    Enable System Restore and immediately create a fresh restore point.
  4. D
    Reconnect the machine to an isolated guest Wi-Fi network to download diagnostic utilities.

Answer

Disable System Restore in Windows to prevent infection points from being backed up or re-infected.
Following isolation of an infected system (Step 2), the mandatory next action in CompTIA's standard 7-step malware removal process is to disable System Restore (Step 3). This ensures that existing restore points containing malicious files are deleted and no new infected points are created before scanning.

Step-by-Step Solution

1
Identify current progress in the 7-step malware remediation procedure.
The technician completed Step 1 (Identify malware symptoms) and Step 2 (Isolate infected system).
The 7-step process requires strict chronological execution.
2
Determine Step 3 of the process.
Step 3 is 'Disable System Restore'.
System Restore must be disabled before running scans or cleaning files to prevent malware from hiding in hidden system volume information checkpoints.

Key Concept

CompTIA 7-Step Malware Remediation Order
Estimated Time:1m 15s
Rate this question