Soru

Zorluk: OrtaMalware Symptoms and Standard Removal Procedures

An IT support technician at a digital animation studio is troubleshooting a Windows 11 workstation. The computer was immediately disconnected from the network after displaying rogue security warnings and initiating unauthorized background network sockets. Having identified the malware symptoms and successfully isolated the machine, which action should the technician take NEXT according to standard CompTIA malware removal procedures?

  1. Disable System Restore in Windows.Cevap
  2. B
    Initiate a full anti-malware system scan using updated definitions.
  3. C
    Enable System Restore and generate a new restore point.
  4. D
    Reconnect the workstation to the local network to download anti-malware updates.

Cevap

Disable System Restore in Windows.
According to CompTIA's standard 7-step malware removal process (1. Identify symptoms, 2. Isolate system, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore/create restore point, 7. Educate user), the immediate next step after isolating the machine is to disable System Restore. This ensures that infected system files are deleted from volume shadow copies and cannot restore the infection later.

Adım Adım Çözüm

1
Review the current state within CompTIA's 7-Step Malware Removal Procedure
Step 1 (Identify malware symptoms) and Step 2 (Isolate infected systems) have already been completed.
The scenario explicitly states that malware symptoms were identified and the workstation was isolated from the network.
2
Determine the mandatory next sequential step in the process
Step 3 is to Disable System Restore (in Windows).
Disabling System Restore cleans out existing restore points and prevents malware from hiding inside Windows volume shadow copies during scanning.

Anahtar Kavram

CompTIA 7-Step Malware Removal Procedure
Bu soruyu puanla