A helpdesk technician at an architectural firm is troubleshooting a Windows 11 workstation that displayed unauthorized pop-ups and erratic process activity. The technician verified the presence of rogue adware and immediately isolated the machine by disconnecting its network cable and turning off wireless connections. According to the CompTIA standard 7-step malware remediation process, which of the following actions should the technician perform NEXT?
- Disable System Restore in Windows to prevent infected system files from being archived.Cevap
- BUpdate the anti-malware definition files and execute a full system scan.
- CRe-enable System Restore and manually create a new restore point.
- DLaunch Event Viewer to clear security logs and reset administrative permissions.
Cevap
Disable System Restore in Windows to prevent infected system files from being archived.
According to the standard CompTIA 7-step malware remediation process, once malware symptoms are identified (Step 1) and the affected system is quarantined (Step 2), the technician must disable System Restore (Step 3). Disabling System Restore deletes existing restore points and prevents the operating system from creating backup copies of infected files during remediation.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Remediation Process Sequence
Tahmini Süre:1m 0s