An IT technician is remediating a severe malware infection on a Windows 11 workstation used in a healthcare clinic's billing department. The technician has confirmed the presence of rogue security software, disconnected all network interfaces, and disabled System Restore. When attempting to launch the local anti-malware utility to scan the system, the malicious process immediately forces the security application to close. Which of the following is the NEXT best step the technician should take to remediate the machine?
- Boot the workstation into Safe Mode or a pre-installation environment to update definitions and run the scanCevap
- BReconnect the network interface cable to allow cloud-based anti-malware signatures to update automatically
- CEnable System Restore and roll back the system to an automatically generated baseline checkpoint
- DExecute the sfc /scannow command from an elevated command prompt to purge active malware processes
Cevap
Boot the workstation into Safe Mode or a pre-installation environment to update definitions and run the scan
When active malware interferes with security tools in standard Windows operational mode, booting into Safe Mode or an isolated pre-installation environment (such as WinPE) prevents third-party malware services and startup hooks from running. This allows the technician to update anti-malware definitions (via USB/offline package) and execute remediation scans successfully as part of Step 4 in the CompTIA removal process.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Remediation Procedure - Step 4 (Remediate Infected Systems)
Tahmini Süre:2m 0s