An IT technician on an offshore logistics terminal is servicing a dedicated cargo-manifest workstation that is infected with persistent ransomware and trojan spyware. The technician has already identified the symptoms and isolated the infected machine from the local area network and wireless access points. According to the CompTIA 7-step malware removal process, which of the following actions must the technician perform NEXT before running a full system scan to remediate the infected endpoint? (Select TWO.)
- Disable System Restore (or System Protection) in the Windows operating system.Cevap
- Update the local anti-malware definition database using an offline update package on a verified USB drive.Cevap
- CCreate an immediate Windows System Restore point to safeguard current configuration settings.
- DConduct an immediate security awareness training session with the workstation operator.
Cevap
The correct actions are disabling System Restore to prevent malware persistence in backups and updating the anti-malware signature definitions via offline media before initiating the scan.
Following system isolation (Step 2), the CompTIA malware removal framework requires disabling System Restore (Step 3) to purge corrupted restore points, followed by updating anti-malware signatures and scanning the environment (Step 4). Because network connectivity is severed during isolation, anti-malware engine definitions must be updated locally using removable media.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Removal Procedure