A workstation on a design team's network displays symptoms of a trojan infection. The IT technician immediately disconnects the Ethernet cable to quarantine the system from the network. What is the next step the technician should perform according to the standard CompTIA malware removal procedures?
- Disable System Restore in WindowsCevap
- BRun a full system anti-malware scan
- CEnable System Restore and create a restore point
- DEducate the user on social engineering threats
Cevap
The technician should disable System Restore in Windows before proceeding with anti-malware scanning or remediation.
Following CompTIA's official 7-step malware remediation process, after identifying the malware and isolating the machine, the technician must disable System Restore before executing remediation tools. This ensures infected files saved inside restore points are cleared.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Removal Procedure