A tier-2 IT support technician at a regional blood bank facility is troubleshooting a Windows 11 workstation used for donor registration. The system is exhibiting active malware symptoms, including unauthorized background network traffic and rogue system notifications. The technician has successfully identified the malware infection and isolated the workstation from the network. Which of the following actions should the technician take NEXT to prepare the machine for remediation prior to executing a full system scan? (Select TWO.)
- Disable System Restore to prevent infected files from being saved in restore points.Answer
- Download the latest anti-malware definition updates on a clean computer and transfer them to the isolated system using removable media.Answer
- CCreate a new system restore point to preserve system state prior to cleaning.
- DTemporarily reconnect the Ethernet cable to enable cloud-based live scanning.
Answer
The technician must disable System Restore to avoid preserving infected files in restore points and download updated anti-malware definitions on an uninfected machine to transfer them via removable media.
According to the CompTIA 7-step malware removal procedure, once a system has been identified as infected and isolated from the network, the next critical step (Step 3) is to disable System Restore. This action purges existing restore points so infected files cannot be restored later. Next, in Step 4 (Remediate), anti-malware signatures must be updated; since the system is disconnected from the network, signatures must be downloaded on an uninfected machine and transferred via removable media.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Procedure - System Restore Disabling and Out-of-Band Definition Updates