A cybersecurity analyst at a research facility is responding to a compromised Windows 11 workstation connected to automated lab sequencing hardware. The machine exhibits persistent pop-up alerts, altered host files, and unauthorized background process creation. The analyst has already isolated the workstation by disabling its network interfaces and has disabled Windows System Restore. Which of the following actions should the analyst perform IMMEDIATELY before launching a full remediation scan on the infected system?
- Update the local anti-malware definition signatures using an offline installation package.Cevap
- BReconnect the network interface temporarily to run a cloud-based web security scanner.
- CRe-enable System Restore and manually create a clean restore point prior to scanning.
- DSchedule recurring OS updates and daily automated background scans in Task Scheduler.
Cevap
Update the local anti-malware definition signatures using an offline installation package.
The scenario describes a system where Step 1 (Identify malware symptoms), Step 2 (Quarantine/Isolate), and Step 3 (Disable System Restore) have already been performed. Step 4 of the CompTIA malware removal process is 'Remediate infected systems,' which explicitly requires updating the anti-malware software and definitions (sub-step 4a) before running scans and using removal techniques (sub-step 4b). Because the workstation is disconnected from the network to maintain isolation, signature updates must be transferred via an offline installation package.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Removal Procedure - Step 4 (Remediate: Update anti-malware software before scanning)
Tahmini Süre:2m 0s