Soru

Zorluk: OrtaMalware Symptoms and Standard Removal Procedures

A desktop technician at a pharmaceutical research laboratory is responding to a Windows workstation compromised by rogue software. Arrange the following remediation actions in the correct chronological sequence according to the CompTIA standard malware removal procedure.

  1. 1Isolate the infected computer by disconnecting all wired network cables and disabling Wi-Fi adapters.
  2. 2Disable Windows System Restore to prevent snapshotting of malicious files.
  3. 3Update anti-malware signature definitions and perform a comprehensive system scan to eliminate threats.
  4. 4Schedule recurring automatic anti-malware scans and configure operating system update settings.
  5. 5Re-enable System Restore and create a fresh system restore point.

Cevap

The correct sequence begins with isolating the infected system from the network, disabling System Restore, updating definitions and remediating the infection through scanning, scheduling future automated scans and updates, and finally re-enabling System Restore to create a clean baseline.
The official CompTIA 7-step malware remediation process dictates a strict linear workflow: 1. Identify symptoms, 2. Isolate infected systems, 3. Disable System Restore, 4. Remediate infected systems (update definitions and perform removal scans), 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, 7. Educate end user. Isolating network connectivity immediately contains the threat. Disabling System Restore ensures malicious payloads are not archived into system backup states. Updating anti-malware signatures and executing scans cleans the OS. Scheduling future scans maintains protection, and re-enabling System Restore provides a clean recovery baseline.

Adım Adım Çözüm

1
Disconnect network interfaces to isolate the infected workstation.
Network communication is severed, stopping potential lateral movement or communication with command-and-control servers.
CompTIA Step 2 requires immediate isolation of the host following symptom identification.
2
Disable System Protection / System Restore in Windows.
Previous restore points containing malware are removed, preventing reinstatement of infected files.
CompTIA Step 3 prevents malware from backing itself up or hiding within system restore snapshots.
3
Download signature updates and run removal scans.
The anti-malware software detects, quarantines, and cleans infected files and registry entries.
CompTIA Step 4 requires updating tools prior to scanning and executing remediation protocols.
4
Establish scheduled automated scans and OS updates.
Ongoing preventative maintenance is configured to prevent reinfection.
CompTIA Step 5 ensures the machine remains safe through proactive scheduling.
5
Turn System Restore back on and generate a new restore point.
A known-good operational baseline is created for future recovery needs.
CompTIA Step 6 reinstates rollback capability only after verifying the workstation is entirely clean.

Anahtar Kavram

CompTIA 7-Step Malware Removal Process
Tahmini Süre:1m 30s
Bu soruyu puanla