An IT support technician at a municipal public library is troubleshooting a Windows workstation that exhibits browser redirects and unexpected background activity. The technician has confirmed a malware infection and isolated the system from the network. According to CompTIA's standard malware removal procedures, which of the following actions should the technician take NEXT before executing a system scan? (Select TWO.)
- Disable System Restore on the infected computer to prevent infected files from being backed up.Cevap
- Update anti-malware signature definitions using an isolated, clean source.Cevap
- CCreate a new System Restore point to preserve the current system state prior to cleaning.
- DReconnect the workstation to the local network to download Windows updates.
Cevap
The technician should disable System Restore to prevent malware persistence and update the anti-malware software definitions using an isolated clean source.
According to CompTIA's 7-step malware removal process (1. Identify, 2. Isolate, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore, 7. Educate end user), after identifying symptoms and isolating the system, the technician must disable System Restore to purge infected points and prevent reinfection. Additionally, prior to scanning during remediation, the technician must update anti-malware signatures, which should be transferred using an isolated/offline media source since the system is disconnected from the network.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Removal Procedure
Tahmini Süre:1m 30s