Soru

Zorluk: ZorMalware Detection, Removal, and Prevention

A field technician is troubleshooting a Windows 11 desktop computer that was flagged for an active Trojan and spyware infection. The technician has already physically disconnected the network cable and turned off Wi-Fi to isolate the host. Which TWO of the following steps should the technician perform NEXT before initiating anti-malware scans and removal tools? (Select TWO.)

  1. Disable System Protection on all local storage volumes.Cevap
  2. Boot the system into Safe Mode or an isolated recovery environment.Cevap
  3. C
    Re-enable System Restore and create a manual system restore point immediately.
  4. D
    Execute `sfc /scannow` from an unprivileged command prompt to delete malicious executable files.

Cevap

The technician must disable System Protection on all local storage volumes and boot the system into Safe Mode or an isolated recovery environment.
Under the standard CompTIA 7-step malware remediation process, once symptoms are identified and the system is quarantined (isolated from the network), the technician must proceed to disable System Restore (Step 3) to clear infected recovery snapshots. Following this, the technician prepares for remediation (Step 4) by updating scanner definitions and booting into Safe Mode to prevent active malware processes from hooking into system memory.

Adım Adım Çözüm

1
Analyze current progress within the CompTIA 7-Step Malware Remediation Process.
Step 1 (Identify malware) and Step 2 (Quarantine infected system) are complete.
The system was identified as infected and isolated from network connections.
2
Perform Step 3: Disable System Restore in Windows.
System Protection is turned off across all local drives, purging existing restore points.
Prevents malware from hiding in hidden system volume information folders or restoring itself after remediation.
3
Prepare for Step 4: Remediate infected systems by isolating execution context.
The machine is booted into Safe Mode.
Prevents malware persistence mechanisms and active rootkits from executing during scanner installation and execution.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Procedure
Tahmini Süre:2m 0s
Bu soruyu puanla