Soru

Zorluk: OrtaMalware Detection, Removal, and Prevention

A desktop technician at a live broadcast news production studio is responding to a malware incident on a Windows 11 workstation. The machine was disconnected from the local network after pop-ups and unusual background network traffic were detected. The technician has confirmed the presence of rogue spyware and has already disabled System Restore on the machine. Which TWO actions should the technician perform NEXT to adhere to the CompTIA 7-step malware remediation process? (Select TWO.)

  1. Update the local anti-malware software engine and definition signatures using an offline installation packageCevap
  2. Perform a full system scan in Safe Mode using specialized anti-malware removal toolsCevap
  3. C
    Re-enable System Restore and create an initial system recovery checkpoint
  4. D
    Configure Windows Task Scheduler to execute daily automated anti-malware scans during off-peak hours
  5. E
    Execute the command 'sfc /scannow /f' inside Windows Task Manager to repair malicious DLL modifications

Cevap

Updating the anti-malware software and definition signatures offline, followed by performing a full system scan in Safe Mode using dedicated removal tools.
According to the CompTIA 7-step malware remediation process, once the technician has identified the symptoms (Step 1), quarantined the system (Step 2), and disabled System Restore (Step 3), the next phase is Step 4: Remediate the infected system. This phase consists of two parts: first updating anti-malware software and signature definitions (Step 4a), and second using scanning and removal techniques such as Safe Mode or pre-boot environments (Step 4b). Updating definitions offline ensures the quarantined system gets the latest signatures without reconnecting to the network.

Adım Adım Çözüm

1
Review the current progress in the 7-step remediation workflow
Steps 1 (Identify), 2 (Quarantine), and 3 (Disable System Restore) are already completed.
Determines the exact position in the standard procedure.
2
Identify the sub-steps of Step 4: Remediate Infected Systems
Step 4a requires updating signatures/definitions (via offline media since the host is quarantined), and Step 4b requires scanning and removing infected files.
Remediation cannot effectively eradicate threats without up-to-date threat signatures and execution in an isolated state like Safe Mode.
3
Select the correct actions matching Step 4a and Step 4b
Updating definitions offline and running a scan in Safe Mode are selected as the immediate next steps.
Subsequent steps like scheduling scans (Step 5), re-enabling System Restore (Step 6), and end-user education (Step 7) must wait until remediation succeeds.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process (Step 4: Remediate Infected Systems)
Bu soruyu puanla