Soru

Zorluk: KolayMalware Detection, Removal, and Prevention

A helpdesk technician has confirmed that a company laptop is infected with a trojan that is generating unauthorized network traffic. Following the standard CompTIA malware remediation process, which action should the technician take NEXT?

  1. Isolate the computer by disconnecting its wired network cable and disabling Wi-Fi.Cevap
  2. B
    Disable System Restore in Windows to prevent infected system backups.
  3. C
    Boot the system into Safe Mode and execute a full anti-malware remediation scan.
  4. D
    Conduct end-user training on how to avoid downloading suspicious email attachments.

Cevap

Isolate the computer by disconnecting its wired network cable and disabling Wi-Fi.
According to the standard CompTIA 7-step malware remediation workflow (1. Identify symptoms, 2. Quarantine infected system, 3. Disable System Restore, 4. Remediate infected system, 5. Schedule updates/scans, 6. Enable System Restore/create restore point, 7. Educate user), the immediate step following symptom identification is quarantining the system. Disconnecting network connections isolates the system to contain the threat.

Adım Adım Çözüm

1
Identify the current step in the CompTIA 7-step malware removal process.
The technician has already identified and verified the malware infection (Step 1).
Recognizing the starting stage determines the proper sequential response.
2
Determine Step 2 of the 7-step malware removal process.
Step 2 is to quarantine the infected system.
Quarantining/isolating the host prevents malware from spreading to other network assets or communicating with external command-and-control servers.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process - Quarantine
Tahmini Süre:1m 0s
Bu soruyu puanla