An IT support specialist at an architectural design firm is servicing a Windows 11 workstation. The computer was immediately disconnected from the local network after displaying unauthorized browser redirects and fake ransomware pop-ups. The specialist has just disabled System Restore on the machine to prevent infected state backups. According to standard CompTIA malware removal procedures, which action should the specialist take NEXT?
- Update anti-malware definitions and execute a comprehensive system scan to quarantine malicious files.Cevap
- BRe-enable System Restore and create an updated restore point to safeguard system settings.
- CReplace the storage drive under the assumption that system degradation and pop-ups indicate hard drive failure.
- DConfigure scheduled automated daily anti-malware scans and verify automatic OS patch deployment.
Cevap
Update anti-malware definitions and execute a comprehensive system scan to quarantine malicious files.
The CompTIA 7-step malware removal workflow follows a mandatory order: 1. Identify malware symptoms, 2. Isolate infected systems, 3. Disable System Restore, 4. Remediate infected systems (update anti-malware signatures, scan, and use removal techniques), 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, and 7. Educate the end user. Since the technician has already isolated the system and disabled System Restore, the immediate next action is Step 4: updating definitions and performing remediation scans.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Removal Process (Step 4: Remediate Infected Systems)
Tahmini Süre:1m 30s