Question

Difficulty: HardMalware Symptoms and Standard Removal Procedures

A tier-2 desktop analyst is remediating a confirmed rootkit and spyware infection on a dedicated workstation at a financial services firm. The analyst has already completed the initial identification of malware symptoms and fully isolated the workstation from the corporate network. According to CompTIA's standard malware removal procedures, which of the following actions should the analyst perform NEXT prior to running local remediation and scanning tools? (Select TWO.)

  1. Disable System Restore in Windows to prevent infected files from being stored in recovery snapshots.Answer
  2. Obtain updated anti-malware definition files from a uncompromised machine and apply them locally via removable media.Answer
  3. C
    Reconnect the workstation's Ethernet interface temporarily to download the latest anti-malware signatures directly from vendor servers.
  4. D
    Re-enable System Restore and manually create a new system baseline restore point before starting the anti-malware scan.

Answer

The specialist must disable System Restore to prevent infected files from persisting in recovery points, and update anti-malware signatures locally using clean removable media while keeping the machine isolated.
Following system isolation (Step 2), the compulsory actions before running anti-malware removal tools (Step 4b) are to turn off/disable System Restore (Step 3) to prevent saving infected files into restore snapshots, and to update anti-malware signatures (Step 4a) out-of-band via clean external storage media to preserve isolation.

Step-by-Step Solution

1
Review current progress in the 7-step malware removal process.
Steps 1 (Identify malware symptoms) and 2 (Isolate infected systems) are complete.
Determines the immediate next mandatory steps in sequence.
2
Disable System Restore (Step 3).
All existing restore points are purged and no new infected points are created.
Prevents malware from lingering in system volume information or being restored inadvertently.
3
Update anti-malware software out-of-band (Step 4a).
Signatures are updated locally without reconnecting the compromised host to the network.
Prepares the anti-malware tool to accurately detect and remove recent threat variants while maintaining complete network isolation.

Key Concept

CompTIA 7-Step Malware Removal Process
Rate this question