Soru

Zorluk: OrtaMalware Detection, Removal, and Prevention

A helpdesk technician at an architectural firm is troubleshooting a Windows 11 workstation that displayed unauthorized pop-ups and erratic process activity. The technician verified the presence of rogue adware and immediately isolated the machine by disconnecting its network cable and turning off wireless connections. According to the CompTIA standard 7-step malware remediation process, which of the following actions should the technician perform NEXT?

  1. Disable System Restore in Windows to prevent infected system files from being archived.Cevap
  2. B
    Update the anti-malware definition files and execute a full system scan.
  3. C
    Re-enable System Restore and manually create a new restore point.
  4. D
    Launch Event Viewer to clear security logs and reset administrative permissions.

Cevap

Disable System Restore in Windows to prevent infected system files from being archived.
According to the standard CompTIA 7-step malware remediation process, once malware symptoms are identified (Step 1) and the affected system is quarantined (Step 2), the technician must disable System Restore (Step 3). Disabling System Restore deletes existing restore points and prevents the operating system from creating backup copies of infected files during remediation.

Adım Adım Çözüm

1
Analyze the current state of the remediation workflow.
Step 1 (Identify malware symptoms) and Step 2 (Quarantine the infected system) have already been completed.
The technician identified rogue adware and disconnected all network interfaces to isolate the device.
2
Determine the next required step in the CompTIA 7-step malware remediation process.
Step 3 specifies disabling System Restore in Windows.
Disabling System Restore clears existing restore points and prevents Windows from automatically capturing infected files or registry keys while remediation is underway.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process Sequence
Tahmini Süre:1m 0s
Bu soruyu puanla