Soru

Zorluk: OrtaMalware Detection, Removal, and Prevention

A systems technician at an architectural design firm is working on a Windows workstation infected with a rogue malware threat. The technician has already identified the malware symptoms, isolated the machine from the local network, and disabled System Restore. Which TWO of the following actions should the technician perform NEXT during the remediation phase of the CompTIA 7-step malware remediation process? (Select TWO.)

  1. Update the anti-malware engine and signature files.Cevap
  2. Perform a complete malware scan using bootable media or Safe Mode.Cevap
  3. C
    Re-enable System Restore and create a fresh system restore point.
  4. D
    Conduct mandatory end-user training on social engineering and web safety.

Cevap

The technician must update the anti-malware engine and signature files, and perform a complete malware scan using bootable media or Safe Mode.
Step 4 of the CompTIA 7-step malware remediation process specifies remediating the infected system by first updating the anti-malware signatures/engine and then performing scan and removal techniques in an isolated environment (such as Safe Mode or WinPE). Both of these actions directly satisfy Step 4.

Adım Adım Çözüm

1
Identify the current step in the CompTIA 7-step malware remediation workflow.
Steps 1 (Identify symptoms), 2 (Quarantine system), and 3 (Disable System Restore) have already been completed.
The next logical phase is Step 4: Remediate infected systems.
2
Determine the required tasks within Step 4 (Remediate infected systems).
Step 4 consists of two sequential actions: (a) Update anti-malware software/signatures, and (b) Scan and use removal techniques (such as Safe Mode or bootable media).
Signatures must be updated prior to running scans so the system can accurately detect and eradicate the identified malware strain.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process
Bu soruyu puanla