An IT support technician at a digital animation studio is troubleshooting a Windows 11 workstation. The computer was immediately disconnected from the network after displaying rogue security warnings and initiating unauthorized background network sockets. Having identified the malware symptoms and successfully isolated the machine, which action should the technician take NEXT according to standard CompTIA malware removal procedures?
- Disable System Restore in Windows.Cevap
- BInitiate a full anti-malware system scan using updated definitions.
- CEnable System Restore and generate a new restore point.
- DReconnect the workstation to the local network to download anti-malware updates.
Cevap
Disable System Restore in Windows.
According to CompTIA's standard 7-step malware removal process (1. Identify symptoms, 2. Isolate system, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore/create restore point, 7. Educate user), the immediate next step after isolating the machine is to disable System Restore. This ensures that infected system files are deleted from volume shadow copies and cannot restore the infection later.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Removal Procedure