A systems administrator at a financial services firm is troubleshooting a workstation infected with a spyware Trojan. The administrator has already identified the malware symptoms and successfully isolated the system from the local network. Which TWO of the following steps should the administrator perform next before initiating scans and removing the infection? (Select TWO.)
- Disable Windows System RestoreAnswer
- Update anti-malware signature definition filesAnswer
- CRe-enable System Restore and create a new restore point
- DProvide end-user awareness training regarding suspicious file downloads
Answer
The administrator should disable Windows System Restore and update anti-malware signature definition files.
Following quarantine, the technician must disable System Restore to ensure that infected system files are not backed up or preserved in system restore points. Immediately after, updating anti-malware signatures ensures that the security engine possesses the newest threat definitions before running full remediation scans.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Remediation Process