A systems administrator at an automated distribution facility notices that a Windows-based picking console is periodically dropping local service responses, running unprompted background tasks, and generating unauthorized outbound connections. The administrator confirms a malware infection and immediately quarantines the console by disconnecting its Ethernet cable and turning off all wireless radios. According to CompTIA's standard 7-step malware removal procedures, which of the following actions should the administrator perform NEXT?
- Disable System Restore in Windows.Cevap
- BBoot the computer into Safe Mode and run a full anti-malware scan using pre-downloaded signature updates.
- CTemporarily re-enable the network interface to download updated malware signature files from an internal repository server.
- DCreate an immediate restore point to save the current configuration in case remediation damages system files.
Cevap
The administrator should disable System Restore in Windows before attempting remediation.
CompTIA's official 7-step malware remediation process specifies the following sequence: 1. Identify malware symptoms, 2. Isolate infected systems, 3. Disable System Restore (in Windows), 4. Remediate infected systems (update anti-malware software / scan and use removal techniques), 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, 7. Educate the end user. Because the technician has already identified the symptoms and isolated the system, the mandatory next step is disabling System Restore.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Remediation Best Practices