An IT technician at a pharmaceutical testing laboratory is responding to a Windows workstation that exhibits heavy background network activity, unauthorized pop-up windows, and degraded performance. The technician confirms the presence of malware. Which TWO of the following actions should the technician take NEXT prior to initiating anti-malware remediation tools?
- Disconnect the workstation's Ethernet cable and disable Wi-Fi adapters.Cevap
- Disable Windows System Restore (System Protection) on the infected workstation.Cevap
- CCreate a new manual system restore point to preserve the OS baseline.
- DSchedule daily automated antimalware scans and system update tasks.
Cevap
The technician must isolate the infected system by disconnecting network interfaces and disable Windows System Restore prior to executing malware remediation.
According to CompTIA's standard 7-step malware removal procedure (1. Identify, 2. Isolate, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore, 7. Educate end user), immediately after identifying the malware symptoms, the technician must isolate the infected system (unplug network interfaces) and disable Windows System Restore before scanning or attempting removal.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Removal Procedure: Step 2 (Isolate) and Step 3 (Disable System Restore) must occur before Step 4 (Remediate).