A desktop technician at a commercial law firm is responding to a Windows workstation displaying unauthorized pop-up security warnings and browser redirects. The technician confirms active malware and immediately disconnects the Ethernet cable to isolate the system from the network. According to the CompTIA standard 7-step malware remediation procedure, which action should the technician take NEXT?
- Disable System Restore in Windows to prevent infection points from being backed up or re-infected.Cevap
- BUpdate anti-malware signatures and perform a comprehensive system scan.
- CEnable System Restore and immediately create a fresh restore point.
- DReconnect the machine to an isolated guest Wi-Fi network to download diagnostic utilities.
Cevap
Disable System Restore in Windows to prevent infection points from being backed up or re-infected.
Following isolation of an infected system (Step 2), the mandatory next action in CompTIA's standard 7-step malware removal process is to disable System Restore (Step 3). This ensures that existing restore points containing malicious files are deleted and no new infected points are created before scanning.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Remediation Order
Tahmini Süre:1m 15s