An enterprise desktop administrator is responding to a malware incident on a Windows 11 workstation. The host has already been physically isolated from the local network, and System Restore has been disabled to prevent malicious persistence in volume shadow copies. Upon attempting to launch the installed anti-malware software to update definition files and clean the system, the malware actively terminates the security application processes and blocks network adapter configuration changes. Which action should the administrator take next to successfully proceed with system remediation?
- Boot the system into Safe Mode or an isolated Pre-installation Environment (PE) to update definitions via clean removable media and execute the remediation scan.Cevap
- BRe-enable System Restore immediately and select a restore point created prior to the infection outbreak to overwrite infected system files.
- COpen Task Manager and end all active background processes running under the Local System and Network Service account privileges.
- DRun the sfc /scannow command from an elevated command prompt to download replacement antivirus signature definitions from Microsoft Update.
Cevap
Boot the system into Safe Mode or an isolated Pre-installation Environment (PE) to update definitions via clean removable media and execute the remediation scan.
According to the CompTIA 7-step malware remediation process, after isolating the system and disabling System Restore, the technician must remediate the machine (Step 4). When active malware prevents normal operation or updates by killing security processes, booting into Safe Mode or using a Pre-installation Environment (PE) bypasses the malware's autostart mechanisms. Signatures can then be loaded from external media and full scans executed.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Remediation Process - Step 4: Remediate Infected Systems
Tahmini Süre:2m 30s