Question

Difficulty: MediumMalware Detection, Removal, and Prevention

A tier-2 helpdesk technician at an electric vehicle charging network operations center is responding to an infected Windows 11 workstation that has already been disconnected and quarantined from the local network. The technician needs to prepare the system for malware removal. According to the standard CompTIA malware remediation process, which TWO of the following actions should the technician perform NEXT before initiating a full system anti-malware scan? (Select TWO.)

  1. Disable System Restore in the Windows System Properties settings.Answer
  2. Update anti-malware signature definitions to the latest engine release.Answer
  3. C
    Re-enable System Restore and create a fresh system restore point.
  4. D
    Execute the sfc /scannow command from an elevated command prompt.

Answer

The technician should disable System Restore and update anti-malware definitions.
Following the CompTIA 7-step malware remediation process, once a system is quarantined (Step 2), the technician must disable System Restore (Step 3) to prevent the OS from creating infected restore points. The next phase is remediation (Step 4), which begins by updating anti-malware signatures (Step 4a) prior to initiating a scan (Step 4b).

Step-by-Step Solution

1
Analyze current progress in the CompTIA 7-step malware remediation process.
Step 1 (Identify malware) and Step 2 (Quarantine infected system) are complete.
The scenario states the workstation has already been identified as infected and quarantined from the network.
2
Identify the immediate next steps (Step 3 and Step 4a).
Step 3 is disabling System Restore. Step 4a is updating anti-malware signatures.
Disabling System Restore prevents infected files from being saved into restore points, and updating anti-malware signatures guarantees that the scanner has the newest threat signatures available.

Key Concept

CompTIA 7-Step Malware Remediation Process
Rate this question