A network administrator detects unauthorized outbound IRC traffic originating from a Windows 11 telemetry workstation located in a remote weather research facility. The administrator successfully disconnects the workstation's network interface and isolates the machine locally. Which action should be performed NEXT in accordance with the standard malware removal procedure before downloading signature updates via out-of-band media and running remediation scans?
- Disable System Restore in WindowsCevap
- BRe-enable the network adapter to allow antimalware tools to perform live database updates
- CCreate an immediate System Restore point to capture the current state prior to file cleaning
- DConfigure scheduled weekly antimalware scans and automatic engine updates
Cevap
Disable System Restore in Windows
Following the compulsory CompTIA 7-step malware remediation process (1. Identify, 2. Isolate, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore and create restore point, 7. Educate end user), after isolating the infected computer (Step 2), the technician must immediately disable System Restore (Step 3). Disabling System Restore deletes existing restore points, ensuring malicious files are not backed up or inadvertently restored later.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Removal Procedure - Step 3 (Disable System Restore)