Soru

Zorluk: KolayMalware Symptoms and Standard Removal Procedures

A workstation on a design team's network displays symptoms of a trojan infection. The IT technician immediately disconnects the Ethernet cable to quarantine the system from the network. What is the next step the technician should perform according to the standard CompTIA malware removal procedures?

  1. Disable System Restore in WindowsCevap
  2. B
    Run a full system anti-malware scan
  3. C
    Enable System Restore and create a restore point
  4. D
    Educate the user on social engineering threats

Cevap

The technician should disable System Restore in Windows before proceeding with anti-malware scanning or remediation.
Following CompTIA's official 7-step malware remediation process, after identifying the malware and isolating the machine, the technician must disable System Restore before executing remediation tools. This ensures infected files saved inside restore points are cleared.

Adım Adım Çözüm

1
Identify current progress in the 7-step malware removal procedure
The technician has completed Step 1 (Identify symptoms) and Step 2 (Isolate the system).
Disconnecting the Ethernet cable represents isolating the infected host.
2
Determine the mandatory next step in the procedure
Step 3 requires disabling System Restore in Windows.
Disabling System Restore purges existing restore points and prevents malware from backing itself up into restore points during scanning.

Anahtar Kavram

CompTIA 7-Step Malware Removal Procedure
Bu soruyu puanla