Soru

Zorluk: OrtaMalware Detection, Removal, and Prevention

A desktop administrator at a commercial airline flight operations center is troubleshooting a Windows 11 workstation infected with a persistent Trojan. The administrator has already verified the malware symptoms, isolated the workstation from the network to quarantine it, disabled System Restore, and updated the anti-malware signature definitions. Which of the following should the administrator perform NEXT according to standard CompTIA malware remediation procedures?

  1. Perform a full system scan using anti-malware software to locate and remove the infection.Cevap
  2. B
    Re-enable System Restore and create a clean system restore point.
  3. C
    Schedule recurring automatic anti-malware scans and OS updates.
  4. D
    Execute the sfc /scannow command from an elevated command prompt to remove malicious files.

Cevap

Perform a full system scan using anti-malware software to locate and remove the infection.
The CompTIA 7-step malware remediation procedure follows a strict sequence: 1. Identify malware symptoms, 2. Quarantine infected systems, 3. Disable System Restore, 4. Remediate infected systems (a. Update signature files, b. Scan and use removal techniques), 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, 7. Educate the user. Since the technician has already updated the signature definitions (Step 4a), the next required action is executing the anti-malware scan to remove the threat (Step 4b).

Adım Adım Çözüm

1
Review the completed steps in the CompTIA 7-step malware remediation process.
Completed: Step 1 (Identify), Step 2 (Quarantine), Step 3 (Disable System Restore), and Step 4a (Update anti-malware signatures).
Tracking progress ensures remediation follows proper sequence without missing key safety measures.
2
Determine the required sub-step for completing remediation (Step 4b).
The technician must execute a full anti-malware scan (in Safe Mode if necessary) to quarantine and remove malicious files.
Updated definitions are ineffective until an active scan is triggered to locate and neutralize the threat.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Best Practices
Tahmini Süre:1m 15s
Bu soruyu puanla