Soru

Zorluk: ZorMalware Detection, Removal, and Prevention

During a security audit at a logistics company, an administrator discovers a Windows 11 workstation exhibiting unauthorized rootkit activity that compromised low-level system drivers. To remediate the breach, the administrator disconnects the network cable, disables System Restore, boots the system into a clean pre-installation environment, and successfully executes a bootable anti-malware utility to eradicate the infection. After booting into Safe Mode and completing a secondary scan that verifies the system is entirely clean, which of the following actions should the administrator take NEXT to follow the standard CompTIA malware remediation process?

  1. Schedule automated anti-malware definition updates and OS patch management.Cevap
  2. B
    Re-enable System Restore and manually create a fresh system restore point.
  3. C
    Reconnect the workstation to the local network domain and conduct end-user security awareness training.
  4. D
    Execute the command sfc /scannow from an elevated command prompt to disable persistence entry points.

Cevap

Schedule automated anti-malware definition updates and OS patch management.
According to the official CompTIA 7-step malware remediation process, the steps must be executed in precise sequential order: 1. Identify malware symptoms, 2. Quarantine infected system, 3. Disable System Restore, 4. Remediate infected systems (update anti-malware / scan and remove), 5. Schedule updates and enable auto-update, 6. Enable System Restore and create a restore point, 7. Educate end user. Because the technician has just finished removing the rootkit and verifying cleanup (Step 4), the required next step is Step 5: scheduling anti-malware definition updates and OS patch management.

Adım Adım Çözüm

1
Identify completed steps in the CompTIA 7-step malware remediation framework
The scenario details that Step 1 (Identify symptoms), Step 2 (Quarantine system), Step 3 (Disable System Restore), and Step 4 (Remediate infected system via offline scanner and secondary Safe Mode verification) have all been completed.
Tracking completed steps prevents skipping mandatory steps or executing tasks out of order.
2
Determine the mandatory next step in the standard process order
Following Step 4 (Remediate infected systems), Step 5 requires scheduling updates and enabling automatic updates for both the OS and security software.
Configuring automatic updates ensures the system is updated with current definitions prior to restoring full system functionality.
3
Select the option that matches Step 5 of the remediation process
Scheduling automated anti-malware definition updates and OS patch management directly corresponds to Step 5.
Subsequent steps, such as re-enabling System Restore (Step 6) and user education (Step 7), must only take place after update schedules are established.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process
Tahmini Süre:2m 0s
Bu soruyu puanla