A systems administrator detects active ransomware activity on a master workstation controlling live digital media encoding streams in a television broadcasting studio. Following the standard CompTIA 7-step malware removal process, in what precise chronological sequence should the administrator perform the following remediation steps?
- 1Disconnect all physical Ethernet cables and disable all wireless network interfaces on the broadcasting workstation.
- 2Turn off Windows System Restore and purge all existing system restore points.
- 3Boot the system into Safe Mode, install the latest signature files via a write-protected USB flash drive, and execute a comprehensive anti-malware scan.
- 4Re-enable Windows System Restore and construct a fresh, uncorrupted system restore baseline point.
- 5Conduct an interactive security awareness training session with the studio broadcast engineers on recognizing spear-phishing attack vectors.
Cevap
The proper sequence follows the CompTIA 7-step malware removal methodology: First, isolate the system by disconnecting network interfaces; second, disable System Restore and delete previous restore points; third, remediate the workstation by updating definitions offline and scanning in Safe Mode; fourth, re-enable System Restore and generate a clean restore point; fifth, educate the end user on security best practices.
CompTIA mandates a strict 7-step malware removal process: 1. Identify malware symptoms, 2. Isolate infected systems, 3. Disable System Restore, 4. Remediate infected systems (update anti-malware and scan), 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, and 7. Educate end user. Network isolation must precede all remediation to halt lateral propagation. Disabling System Restore deletes infected recovery snapshots. Remediating eradicates the active infection. System Restore is re-enabled only when the system is verified clean, followed finally by user education.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Removal Best Practices