Soru

Zorluk: KolayMalware Symptoms and Standard Removal Procedures

A receptionist at a medical clinic reports that a Windows workstation used for check-ins is displaying unexpected adware pop-ups and generating heavy unauthorized network traffic. A technician inspects the system and confirms an active malware infection. According to the CompTIA standard 7-step malware removal process, which of the following actions should the technician perform IMMEDIATELY after identifying the infection?

  1. A
    Disable System Restore in Windows settings
  2. Disconnect the workstation from the networkCevap
  3. C
    Perform a full system scan using updated antivirus signatures
  4. D
    Train the receptionist on identifying suspicious web links

Cevap

Disconnect the workstation from the network
Following the CompTIA 7-step malware removal process (1. Identify symptoms, 2. Isolate infected system, 3. Disable System Restore, 4. Remediate infected system, 5. Schedule scans and updates, 6. Enable System Restore, 7. Educate end user), the immediate next step after identifying malware is to isolate the system by disconnecting it from wired or wireless networks.

Adım Adım Çözüm

1
Identify the current step in the CompTIA 7-step malware removal workflow
The scenario states that the technician has already confirmed the malware infection (Step 1: Identify malware symptoms).
Determining the current phase dictates what action must follow immediately.
2
Determine the next sequential step in the process
Step 2 is to isolate the infected system.
Isolating the device by unplugging the Ethernet cable or disconnecting Wi-Fi prevents malware from spreading to other network assets or exfiltrating data.

Anahtar Kavram

CompTIA 7-Step Malware Removal Procedure (Step 2: Isolate infected systems)
Tahmini Süre:45s
Bu soruyu puanla