A desktop technician at an autonomous agricultural equipment monitoring facility is remediating a Windows 11 workstation infected with rogue adware and tracking spyware. The technician has already identified the malware symptoms on the system. Place the following remediation steps in the correct order to resolve the incident according to CompTIA best practices.
- 1Disconnect the infected workstation from the local network by disabling its wireless interface and unplugging the Ethernet cable.
- 2Disable Windows System Restore on the workstation.
- 3Update anti-malware signatures from a clean system and execute a full anti-malware scan to remove infected files.
- 4Re-enable Windows System Restore and create a new system restore point.
- 5Conduct security awareness training with the equipment operator on safe web browsing and threat avoidance.
Cevap
The correct order of remediation steps is: 1) Disconnect the infected workstation from the network, 2) Disable Windows System Restore, 3) Update anti-malware signatures and execute a full scan, 4) Re-enable Windows System Restore and create a new restore point, 5) Conduct security awareness training with the operator.
The standard CompTIA 7-step malware removal process must be performed in exact sequence: (1) Identify malware symptoms, (2) Quarantine infected systems, (3) Disable System Restore, (4) Remediate infected systems (update definitions then scan/use removal tools), (5) Schedule updates and scans, (6) Enable System Restore and create a restore point, and (7) Educate the end user. Following this sequence isolates the threat early, prevents malware persistence in recovery points, cleans the system thoroughly, re-establishes protection baselines, and mitigates future occurrences.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Remediation Best Practices