An IT support technician at a maritime shipping terminal is troubleshooting a Windows 11 workstation used for cargo container tracking. The workstation was isolated from the local network after exhibiting unauthorized background network connections and browser redirects. The technician has already disabled System Restore on the machine to prevent infected restoration files. Which of the following actions should the technician perform NEXT according to the standard CompTIA 7-step malware removal procedure?
- Update the anti-malware definitions and software engine using a clean external media source.Cevap
- BRe-enable System Restore and manually create a new system restoration point.
- CSchedule recurring daily anti-malware scans and Windows OS updates.
- DProvide cybersecurity awareness training to the terminal staff regarding safe browsing practices.
Cevap
Update the anti-malware definitions and software engine using a clean external media source.
Following the CompTIA 7-step malware removal process (1. Identify, 2. Isolate, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore, 7. Educate end user), the immediate next step after disabling System Restore is Step 4: Remediate infected systems. Remediation begins by updating anti-malware definitions and engine software (Step 4a) prior to scanning and executing removal techniques (Step 4b). Because the workstation is isolated from the network, transferring updated definitions via clean external media is the correct procedural action.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Removal Procedure
Tahmini Süre:1m 0s