A tier-2 desktop technician at an educational publishing firm has completed scanning and successfully removed a persistent rootkit infection from an isolated Windows 11 workstation. The technician has also configured scheduled automated daily anti-malware scans and system updates. Which of the following steps should the technician perform NEXT in the standard CompTIA malware remediation workflow?
- Enable System Restore and create a new system restore point.Cevap
- BConduct security awareness training with the end user regarding safe browsing habits.
- COpen Event Viewer to force the download of updated anti-malware definition files.
- DRun the command chkdsk /f to purge volatile malware artifacts from system memory.
Cevap
Enable System Restore and create a new system restore point.
According to the official CompTIA 7-step malware remediation process, the steps are: 1. Identify symptoms, 2. Quarantine infected system, 3. Disable System Restore, 4. Remediate infected systems (update anti-malware and scan/remove), 5. Schedule updates and run scans, 6. Enable System Restore and create a restore point, and 7. Educate the end user. Since steps 1 through 5 have been completed, the technician must now enable System Restore and create a clean restore point.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Remediation Process