A systems administrator suspects that a network-connected Windows 11 workstation at a renewable energy research facility is infected with malware after observing unexpected outbound data transfers and rogue pop-up notifications. Following CompTIA's standard 7-step malware removal procedure, which of the following actions should the administrator take BEFORE initializing anti-malware scanning tools? (Select TWO.)
- Disconnect physical network cables and disable all wireless network interfaces on the affected workstation.Cevap
- Disable System Restore in Windows to prevent infected files from being saved in system restore points.Cevap
- CRe-enable System Restore and generate an immediate restore point prior to running removal tools.
- DConduct end-user training on recognizing social engineering tactics and suspicious email attachments.
Cevap
The administrator should disconnect physical network cables and disable all wireless network interfaces on the affected workstation, as well as disable System Restore in Windows to prevent infected files from being saved in system restore points.
According to CompTIA's 7-step malware removal procedure, once symptoms are identified (Step 1), the immediate subsequent actions required before remediation and scanning (Step 4) are isolating the infected system (Step 2) by disconnecting all network interfaces, and disabling System Restore (Step 3) to clear any restore points that might contain malicious files.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-step malware removal procedure order of execution