An IT technician is responding to a confirmed malware infection on a Windows 11 workstation operating inside a pharmaceutical cleanroom environment. The technician has already identified the symptoms and isolated the workstation from the facility network by disconnecting its Ethernet cable. According to standard CompTIA malware removal procedures, which of the following actions should the technician perform NEXT before initiating full antimalware scanning and remediation? (Select TWO.)
- Disable System Protection (System Restore) on the affected system.Answer
- Obtain the latest antimalware definition files using a clean computer and transfer them to the isolated system.Answer
- CCreate an immediate system restore point to preserve system configuration settings before attempting cleanup.
- DTemporarily reconnect the network cable to allow the antimalware tool to pull live updates from cloud servers.
- EProvide immediate end-user security awareness training to the cleanroom operators regarding safe browsing.
Answer
The technician should disable System Protection (System Restore) and obtain updated antimalware definitions using an uninfected computer via offline media.
According to CompTIA standard malware remediation procedures, after identifying symptoms (Step 1) and isolating the system (Step 2), the technician must disable System Restore (Step 3) to prevent infected files from being saved into backup restore points. Next, as part of remediation (Step 4), the technician must update antimalware definitions; since the device is isolated, definitions should be downloaded on an uninfected machine and transferred offline.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Remediation Workflow (Steps 3 and 4a)