Soru

Zorluk: Çok zorMalware Symptoms and Standard Removal Procedures

An IT technician on an offshore logistics terminal is servicing a dedicated cargo-manifest workstation that is infected with persistent ransomware and trojan spyware. The technician has already identified the symptoms and isolated the infected machine from the local area network and wireless access points. According to the CompTIA 7-step malware removal process, which of the following actions must the technician perform NEXT before running a full system scan to remediate the infected endpoint? (Select TWO.)

  1. Disable System Restore (or System Protection) in the Windows operating system.Cevap
  2. Update the local anti-malware definition database using an offline update package on a verified USB drive.Cevap
  3. C
    Create an immediate Windows System Restore point to safeguard current configuration settings.
  4. D
    Conduct an immediate security awareness training session with the workstation operator.

Cevap

The correct actions are disabling System Restore to prevent malware persistence in backups and updating the anti-malware signature definitions via offline media before initiating the scan.
Following system isolation (Step 2), the CompTIA malware removal framework requires disabling System Restore (Step 3) to purge corrupted restore points, followed by updating anti-malware signatures and scanning the environment (Step 4). Because network connectivity is severed during isolation, anti-malware engine definitions must be updated locally using removable media.

Adım Adım Çözüm

1
Review the current phase within the CompTIA 7-step malware removal process.
Step 1 (Identify symptoms) and Step 2 (Isolate system) are already complete.
The scenario states the technician has identified the infection and disconnected all network connections.
2
Execute Step 3 of the process: Disable System Restore.
System Restore is turned off, clearing unverified restore points that may contain malicious payloads.
Malware frequently hides in restore points or relies on system restore to reinstate itself after deletion.
3
Execute Step 4a of the process: Update anti-malware signatures.
Anti-malware definitions are updated manually using removable offline media.
Because the endpoint remains isolated from the network, online updates are impossible; definitions must be updated manually prior to scanning.

Anahtar Kavram

CompTIA 7-Step Malware Removal Procedure
Bu soruyu puanla