Soru

Zorluk: Çok zorMalware Detection, Removal, and Prevention

A cybersecurity technician is resolving a security incident on a corporate endpoint. The technician identified a stealth keylogger infection, isolated the system from the network, disabled System Restore, updated the security software in Safe Mode, and successfully completed malware removal and verification. Which of the following actions must the technician perform next to adhere to the standard CompTIA malware remediation process?

  1. Configure scheduled operating system updates and automated anti-malware scans.Cevap
  2. B
    Re-enable System Restore and create an immediate system restore point.
  3. C
    Conduct a security awareness briefing with the user regarding threat vectors and prevention.
  4. D
    Reconnect the endpoint to the production network and monitor Event Viewer logs.

Cevap

Configure scheduled operating system updates and automated anti-malware scans.
According to the standard CompTIA 7-step malware remediation framework, the steps must be performed in exact sequence: 1) Identify symptoms, 2) Quarantine infected system, 3) Disable System Restore, 4) Remediate infected systems (update anti-malware and scan/remove), 5) Schedule updates and run recurring scans, 6) Enable System Restore and create a restore point, 7) Educate the user. Since the scenario completes Step 4 (remediation and removal), the immediate next step required is Step 5 (scheduling updates and recurring scans).

Adım Adım Çözüm

1
Review the completed steps against the CompTIA 7-step malware remediation framework.
Steps 1 (Identify), 2 (Quarantine), 3 (Disable System Restore), and 4 (Remediate/Remove malware) have been performed.
Tracking completed steps identifies where the technician currently sits in the remediation workflow.
2
Identify the mandatory next sequence step following Step 4 (Remediate infected systems).
Step 5 is 'Schedule updates and run recurring scans'.
Scheduling updates and scans ensures continuous protection against recurring or unpatched vulnerabilities before enabling restore capabilities.
3
Select the option representing Step 5.
Configuring scheduled OS updates and automated anti-malware scans is selected.
This matches the exact procedural requirement of Step 5.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process
Bu soruyu puanla