Soru

Zorluk: ZorMalware Detection, Removal, and Prevention

A network administrator isolates a Windows workstation after detecting an active rootkit that intercepted system calls and modified core system files. The technician has successfully quarantined the machine from the network and disabled System Restore. To proceed with the remediation phase according to the standard CompTIA malware removal process, which of the following actions should the technician take? (Select TWO.)

  1. Update local anti-malware definitions using an isolated media source or internal update server.Cevap
  2. Boot into Safe Mode or an isolated pre-installation environment to perform a full system anti-malware scan.Cevap
  3. C
    Re-enable System Restore and generate a fresh restore point prior to launching remediation tools.
  4. D
    Use the Event Viewer MMC snap-in to automatically purge malicious system driver entries.

Cevap

Updating anti-malware definitions from a clean source and performing a full scan in Safe Mode or a clean pre-boot environment are the correct remediation actions.
Updating anti-malware signatures from a trusted offline or internal source and executing scans in Safe Mode or a pre-installation environment represent the key tasks of Step 4 (Remediate infected systems) in the CompTIA 7-step process. Safe Mode prevents rootkits and trojans from locking system resources during removal.

Adım Adım Çözüm

1
Identify the current step in the CompTIA 7-step malware removal workflow.
The technician has already completed Step 1 (Identify malware symptoms), Step 2 (Quarantine infected systems), and Step 3 (Disable System Restore). Step 4 is Remediate Infected Systems.
The process must follow the strict standard sequence.
2
Select appropriate actions for Step 4 (Remediate infected systems).
Step 4 requires updating signature files/engines from an uncompromised location and running anti-malware tools (often in Safe Mode or a pre-boot environment to bypass active rootkits).
Rootkits hook OS APIs when running normally, making pre-boot or Safe Mode scanning mandatory for thorough detection and removal.
3
Evaluate distractors against the 7-step process and tool capabilities.
Re-enabling System Restore prematurely violates Step 6 rules, and Event Viewer cannot quarantine files.
System Restore is only re-enabled after infection removal is verified, and log viewers are passive tools.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process: Remediate Infected Systems
Tahmini Süre:2m 0s
Bu soruyu puanla