A IT support specialist at a municipal utility district is responding to a Windows 11 desktop computer that exhibits symptoms of a malware infection. The technician has confirmed the presence of malicious processes and has completely isolated the workstation from the network by disconnecting the Ethernet cable and disabling all wireless radios. Following CompTIA's standard 7-step malware removal procedure, which of the following actions should the technician take NEXT?
- Disable Windows System Restore on the infected workstation.Cevap
- BRe-enable System Restore and generate a fresh restore point immediately.
- CReplace the motherboard network interface card to resolve suspected packet loss.
- DConduct end-user cybersecurity training on recognizing phishing links.
Cevap
The technician should disable Windows System Restore on the infected workstation.
In CompTIA's standard 7-step malware remediation process, Step 3 requires disabling System Restore immediately after isolating the infected system (Step 2). Disabling System Restore deletes existing restore points, ensuring that infected copies of files cannot persist or be restored later.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Removal Procedure
Tahmini Süre:1m 0s