Soru

Zorluk: OrtaMalware Symptoms and Standard Removal Procedures

A desktop support technician is troubleshooting a Windows 11 workstation used by a CAD drafter at an architectural design firm. The computer exhibits unauthorized pop-up windows and modified browser search engine settings. The technician has confirmed the presence of malware and disconnected the physical network cable to isolate the system. Which of the following is the NEXT step the technician should take according to the standard CompTIA malware removal procedures?

  1. Disable System Restore in Windows.Cevap
  2. B
    Run a full system anti-malware scan using existing definitions.
  3. C
    Create a new manual restore point to save the current configuration.
  4. D
    Reconnect the network cable briefly to update the anti-malware signatures.

Cevap

Disable System Restore in Windows.
According to CompTIA's standard 7-step malware remediation procedure (1. Identify, 2. Isolate, 3. Disable System Restore, 4. Remediate infected systems, 5. Schedule scans/updates, 6. Enable System Restore & create restore point, 7. Educate end user), the immediate step following isolation of the infected system is disabling System Restore. Disabling System Restore purges existing system protection snapshots, ensuring infected system files cannot persist or be restored later.

Adım Adım Çözüm

1
Identify the current stage within CompTIA's 7-step malware removal process.
The technician has completed Step 1 (Identify malware symptoms) and Step 2 (Isolate infected systems).
Determining the completed steps establishes where the technician is in the mandatory order of operations.
2
Determine the required third step of the removal process.
Step 3 requires disabling System Restore in Windows.
Disabling System Restore clears existing restore points and prevents malware from surviving remediation by concealing infected copies inside Windows restore points.

Anahtar Kavram

CompTIA 7-Step Malware Removal Procedure
Bu soruyu puanla