Soru

Zorluk: Çok zorMalware Symptoms and Standard Removal Procedures

A cybersecurity analyst at a research facility is responding to a compromised Windows 11 workstation connected to automated lab sequencing hardware. The machine exhibits persistent pop-up alerts, altered host files, and unauthorized background process creation. The analyst has already isolated the workstation by disabling its network interfaces and has disabled Windows System Restore. Which of the following actions should the analyst perform IMMEDIATELY before launching a full remediation scan on the infected system?

  1. Update the local anti-malware definition signatures using an offline installation package.Cevap
  2. B
    Reconnect the network interface temporarily to run a cloud-based web security scanner.
  3. C
    Re-enable System Restore and manually create a clean restore point prior to scanning.
  4. D
    Schedule recurring OS updates and daily automated background scans in Task Scheduler.

Cevap

Update the local anti-malware definition signatures using an offline installation package.
The scenario describes a system where Step 1 (Identify malware symptoms), Step 2 (Quarantine/Isolate), and Step 3 (Disable System Restore) have already been performed. Step 4 of the CompTIA malware removal process is 'Remediate infected systems,' which explicitly requires updating the anti-malware software and definitions (sub-step 4a) before running scans and using removal techniques (sub-step 4b). Because the workstation is disconnected from the network to maintain isolation, signature updates must be transferred via an offline installation package.

Adım Adım Çözüm

1
Analyze the current state within CompTIA's 7-step malware removal framework.
The technician has completed Step 1 (Identify symptoms), Step 2 (Quarantine/Isolate system), and Step 3 (Disable System Restore).
Establishing the current phase in the standard workflow dictates the required next action.
2
Identify the sub-steps of Step 4 (Remediate infected systems).
Step 4 requires updating the anti-malware engine/signatures first (Step 4a) before running scans and removal tools (Step 4b).
Scanning with outdated definition files may miss newly mutated malware signatures or rootkit payloads.
3
Determine the proper method for updating signatures on an isolated system.
Because the system is isolated from the network, signatures must be updated offline via removable media containing signed signature packages.
Maintaining network isolation prevents malware propagation while providing the scanner with current detection signatures.

Anahtar Kavram

CompTIA 7-Step Malware Removal Procedure - Step 4 (Remediate: Update anti-malware software before scanning)
Tahmini Süre:2m 0s
Bu soruyu puanla