A cybersecurity technician is resolving a security incident on a corporate endpoint. The technician identified a stealth keylogger infection, isolated the system from the network, disabled System Restore, updated the security software in Safe Mode, and successfully completed malware removal and verification. Which of the following actions must the technician perform next to adhere to the standard CompTIA malware remediation process?
- Configure scheduled operating system updates and automated anti-malware scans.Cevap
- BRe-enable System Restore and create an immediate system restore point.
- CConduct a security awareness briefing with the user regarding threat vectors and prevention.
- DReconnect the endpoint to the production network and monitor Event Viewer logs.
Cevap
Configure scheduled operating system updates and automated anti-malware scans.
According to the standard CompTIA 7-step malware remediation framework, the steps must be performed in exact sequence: 1) Identify symptoms, 2) Quarantine infected system, 3) Disable System Restore, 4) Remediate infected systems (update anti-malware and scan/remove), 5) Schedule updates and run recurring scans, 6) Enable System Restore and create a restore point, 7) Educate the user. Since the scenario completes Step 4 (remediation and removal), the immediate next step required is Step 5 (scheduling updates and recurring scans).
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Remediation Process