Soru

Zorluk: OrtaMalware Symptoms and Standard Removal Procedures

A IT support specialist at a municipal utility district is responding to a Windows 11 desktop computer that exhibits symptoms of a malware infection. The technician has confirmed the presence of malicious processes and has completely isolated the workstation from the network by disconnecting the Ethernet cable and disabling all wireless radios. Following CompTIA's standard 7-step malware removal procedure, which of the following actions should the technician take NEXT?

  1. Disable Windows System Restore on the infected workstation.Cevap
  2. B
    Re-enable System Restore and generate a fresh restore point immediately.
  3. C
    Replace the motherboard network interface card to resolve suspected packet loss.
  4. D
    Conduct end-user cybersecurity training on recognizing phishing links.

Cevap

The technician should disable Windows System Restore on the infected workstation.
In CompTIA's standard 7-step malware remediation process, Step 3 requires disabling System Restore immediately after isolating the infected system (Step 2). Disabling System Restore deletes existing restore points, ensuring that infected copies of files cannot persist or be restored later.

Adım Adım Çözüm

1
Identify the current step completed in the CompTIA 7-step malware removal process.
Step 1 (Identify malware symptoms) and Step 2 (Isolate infected systems) have already been completed.
The scenario explicitly states symptoms were identified and the machine was isolated from Ethernet/Wi-Fi.
2
Determine the mandatory next step in the standard sequence.
Step 3 is to disable System Restore.
Disabling System Restore prevents infected files from being saved into restore points or restored unintentionally during cleanup.

Anahtar Kavram

CompTIA 7-Step Malware Removal Procedure
Tahmini Süre:1m 0s
Bu soruyu puanla