A field systems engineer is servicing a Windows workstation at a remote branch office after local endpoint monitoring software flagged rogue keylogger activity. The engineer has physically disconnected the machine from the network, verified that the host is fully quarantined, and downloaded the latest anti-malware definition signatures onto an isolated USB drive. Which step must the engineer perform NEXT in accordance with standard malware remediation procedures prior to executing the scan and removal process?
- Disable System Restore in Windows.Cevap
- BSchedule recurring anti-malware updates and daily background scans.
- CCreate a new System Restore point to save the current driver configuration.
- DExecute `chkdsk /r` from an elevated command prompt to repair file system allocation tables.
Cevap
Disable System Restore in Windows before running the anti-malware remediation scan.
According to the official CompTIA 7-step malware remediation process, the exact sequence is: 1. Identify malware symptoms, 2. Quarantine infected systems, 3. Disable System Restore, 4. Remediate infected systems (update anti-malware signatures, scan, and remove), 5. Schedule updates and scans, 6. Enable System Restore and create a restore point, 7. Educate the end user. Since the system has already been quarantined and update files obtained, the required next step before performing the remediation scan is to disable System Restore.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Remediation Process Order
Tahmini Süre:2m 0s