A systems administrator is responding to an alert on a standalone Windows point-of-sale terminal that is exhibiting unauthorized background network connections and altered registry run keys. The administrator has verified the malware infection and immediately unplugged the network cable to isolate the workstation. According to CompTIA's standard 7-step malware removal procedures, which of the following actions should the administrator perform NEXT?
- Disable System Restore and delete all existing restore points on the infected workstation.Answer
- BUpdate the local anti-malware signature file via external storage and execute a comprehensive remediation scan.
- CReconnect the endpoint to an isolated management VLAN to enable remote anti-malware updates and centralized monitoring.
- DOpen Event Viewer to review the Security log for unauthorized authentication attempts and document the incident.
Answer
Disable System Restore and delete all existing restore points on the infected workstation.
The official CompTIA 7-step malware removal process follows this exact order: 1. Identify malware symptoms, 2. Isolate infected systems, 3. Disable System Restore (in Windows), 4. Remediate infected systems (update anti-malware / scan and remove), 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, 7. Educate the end user. Since the scenario explicitly confirms that identification and isolation have taken place, the administrator must immediately disable System Restore to purge infected restore points.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Procedure Sequence