Soru

Zorluk: OrtaMalware Symptoms and Standard Removal Procedures

A desktop technician is responding to a suspected ransomware infection on a workstation used by a rare manuscripts archivist at a university library. The technician needs to execute the standard CompTIA malware removal process. Place the following remediation actions in the correct chronological order from first to last.

  1. 1Disconnect the workstation from the Ethernet network and disable all wireless radios.
  2. 2Disable Windows System Restore to prevent malware copies from persisting in shadow copies.
  3. 3Update anti-malware signatures to the latest release and perform a comprehensive system scan.
  4. 4Re-enable System Restore and manually create a clean restore point.
  5. 5Provide security awareness guidance to the archivist regarding suspicious file downloads.

Cevap

The correct chronological sequence for CompTIA malware removal is: 1) Disconnect the workstation from the network, 2) Disable Windows System Restore, 3) Update anti-malware signatures and perform a comprehensive system scan, 4) Re-enable System Restore and manually create a clean restore point, and 5) Provide security awareness guidance to the archivist.
CompTIA defines a strict 7-step malware removal procedure: 1. Identify malware symptoms, 2. Isolate infected systems, 3. Disable System Restore, 4. Remediate infected systems (update definitions & scan/remove), 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, and 7. Educate the end user. Arranging the actions following this standard workflow places network isolation first, followed by disabling restore features, executing scans/remediation, generating a new clean restore point, and concluding with user education.

Adım Adım Çözüm

1
Isolate the infected machine immediately
Network communication is terminated, stopping malware from spreading to library shares.
Isolation must occur right after identifying symptoms to protect adjacent network infrastructure.
2
Turn off System Restore in Windows
Existing restore points containing malware binaries are cleared.
Prevents accidental restoration of infected system files later.
3
Remediate by updating definitions and scanning
Malware files, registry keys, and active processes are identified and quarantined.
Ensures the anti-malware engine uses current threat signatures to eradicate the payload.
4
Enable System Restore and create a clean restore point
A known-good baseline recovery point is established.
Restores protection capabilities only after verifying the operating system is completely clean.
5
Educate the user
The archivist learns best practices to prevent similar future infections.
Finalizes the remediation lifecycle by addressing human risk factors.

Anahtar Kavram

CompTIA 7-Step Malware Removal Procedure
Tahmini Süre:1m 30s
Bu soruyu puanla