Soru

Zorluk: OrtaMalware Detection, Removal, and Prevention

A desktop support specialist at a corporate law firm is responding to an infected Windows 11 workstation exhibiting rogue security alerts and unauthorized background network traffic. The specialist has verified the malware infection and disconnected the system from the local network to quarantine it. Which TWO of the following actions should the specialist perform NEXT prior to running a full anti-malware remediation scan?

  1. Disable System Restore in Windows to prevent infected system files from being archived in restore points.Cevap
  2. Update the anti-malware software definitions using an external, uninfected source while keeping the machine offline.Cevap
  3. C
    Enable System Restore and generate an immediate restore point to save the current system state prior to cleaning.
  4. D
    Execute sfc /scannow from a standard user command prompt to repair corrupted system files.

Cevap

The technician should disable System Restore in Windows to eliminate infected restore points and update the anti-malware definitions using clean external media before scanning.
According to the official CompTIA 7-step malware remediation process, after identifying the malware (Step 1) and quarantining the infected system (Step 2), the technician must next disable System Restore (Step 3) to delete infected restore points and prevent reinfection. Following that, the technician must remediate the system (Step 4), which begins by updating the anti-malware engine and signature definitions (Step 4a). Since the system is isolated from the network, definitions should be obtained from an uninfected computer and loaded manually via external media.

Adım Adım Çözüm

1
Identify the current step in the CompTIA 7-Step Malware Remediation Process.
The scenario states that Step 1 (Identify malware symptoms) and Step 2 (Quarantine infected systems) have already occurred.
Knowing the starting phase determines the required sequential actions.
2
Execute Step 3 of the remediation framework.
Disable System Restore in Windows settings.
Disabling System Restore clears existing restore points so infected malware binaries cannot persist across recovery points.
3
Execute Step 4a of the remediation framework.
Update the anti-malware signatures/definitions.
Scans require the latest virus signatures to detect and remove modern threat strains effectively.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process Order
Tahmini Süre:1m 30s
Bu soruyu puanla