A systems administrator suspects that a Windows workstation on the corporate network is infected with a trojan after observing suspicious background network traffic. The administrator has already disconnected the workstation from the network to quarantine it and has disabled System Restore. According to the standard CompTIA malware remediation procedure, which of the following actions should the administrator take NEXT?
- Update the anti-malware software definitions and perform a complete system scan.Cevap
- BSchedule recurring automated anti-malware scans and verify that operating system updates are installed.
- CRe-enable System Restore and create a fresh restore point for the system.
- DConduct a security awareness training session for the affected employee.
Cevap
Update the anti-malware software definitions and perform a complete system scan.
The CompTIA 7-step malware remediation workflow follows a strict sequence: (1) Identify malware symptoms, (2) Quarantine infected systems, (3) Disable System Restore, (4) Remediate infected systems (update signatures and scan/remove), (5) Schedule updates and install OS patches, (6) Enable System Restore and create a restore point, and (7) Educate the end user. Since steps 1 through 3 are already completed, the next logical and required step is remediation via anti-malware updates and scanning.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Remediation Process
Tahmini Süre:45s