Soru

Zorluk: OrtaMalware Detection, Removal, and Prevention

A systems administrator at a municipal transit operations center is following the standard CompTIA seven-step malware remediation workflow to resolve a malware infection on a Windows workstation. The administrator has already quarantined the machine, disabled System Restore, updated anti-malware signatures, scanned and removed the malicious files, and configured scheduled automatic scans and updates. Which step should the administrator perform NEXT?

  1. Enable System Restore and create a new restore point.Cevap
  2. B
    Educate the end user on security awareness and malware prevention techniques.
  3. C
    Run sfc /scannow from an elevated command prompt to repair modified system files.
  4. D
    Unquarantine the workstation and reconnect it to the internal network segment.

Cevap

Enable System Restore and create a new restore point.
The correct response is to enable System Restore and create a new restore point. In the CompTIA 7-step malware remediation process, Step 6 requires technicians to re-enable System Restore and create a fresh restore point after the system has been cleaned (Step 4) and automatic updates/scans have been scheduled (Step 5). This ensures the OS has a known-good recovery point free of malware infections.

Adım Adım Çözüm

1
Review the completed steps in the CompTIA 7-step malware remediation process.
Steps 1 through 5 (Identify, Quarantine, Disable System Restore, Remediate/Scan, Schedule Updates/Scans) are verified as complete.
Tracking current remediation progress ensures steps are executed in the mandated sequence.
2
Identify the next sequential step following Step 5 (Schedule updates and run scans).
Step 6 is to Enable System Restore and create a new restore point.
System Restore was disabled earlier to prevent reinfection from corrupted restore points; re-enabling it now creates a clean post-remediation baseline.
3
Confirm the remaining step.
Step 7 (Educate the end user) will be performed after Step 6.
Creating a clean restore point must happen before final user handoff and education.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Best Practices
Tahmini Süre:1m 0s
Bu soruyu puanla