A network administrator isolates a Windows workstation after detecting an active rootkit that intercepted system calls and modified core system files. The technician has successfully quarantined the machine from the network and disabled System Restore. To proceed with the remediation phase according to the standard CompTIA malware removal process, which of the following actions should the technician take? (Select TWO.)
- Update local anti-malware definitions using an isolated media source or internal update server.Cevap
- Boot into Safe Mode or an isolated pre-installation environment to perform a full system anti-malware scan.Cevap
- CRe-enable System Restore and generate a fresh restore point prior to launching remediation tools.
- DUse the Event Viewer MMC snap-in to automatically purge malicious system driver entries.
Cevap
Updating anti-malware definitions from a clean source and performing a full scan in Safe Mode or a clean pre-boot environment are the correct remediation actions.
Updating anti-malware signatures from a trusted offline or internal source and executing scans in Safe Mode or a pre-installation environment represent the key tasks of Step 4 (Remediate infected systems) in the CompTIA 7-step process. Safe Mode prevents rootkits and trojans from locking system resources during removal.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Remediation Process: Remediate Infected Systems
Tahmini Süre:2m 0s