Soru

Zorluk: OrtaMalware Symptoms and Standard Removal Procedures

A tier-2 IT support technician at a regional blood bank facility is troubleshooting a Windows 11 workstation used for donor registration. The system is exhibiting active malware symptoms, including unauthorized background network traffic and rogue system notifications. The technician has successfully identified the malware infection and isolated the workstation from the network. Which of the following actions should the technician take NEXT to prepare the machine for remediation prior to executing a full system scan? (Select TWO.)

  1. Disable System Restore to prevent infected files from being saved in restore points.Cevap
  2. Download the latest anti-malware definition updates on a clean computer and transfer them to the isolated system using removable media.Cevap
  3. C
    Create a new system restore point to preserve system state prior to cleaning.
  4. D
    Temporarily reconnect the Ethernet cable to enable cloud-based live scanning.

Cevap

The technician must disable System Restore to avoid preserving infected files in restore points and download updated anti-malware definitions on an uninfected machine to transfer them via removable media.
According to the CompTIA 7-step malware removal procedure, once a system has been identified as infected and isolated from the network, the next critical step (Step 3) is to disable System Restore. This action purges existing restore points so infected files cannot be restored later. Next, in Step 4 (Remediate), anti-malware signatures must be updated; since the system is disconnected from the network, signatures must be downloaded on an uninfected machine and transferred via removable media.

Adım Adım Çözüm

1
Review the CompTIA 7-step malware remediation process sequence
Determine that after Step 1 (Identify) and Step 2 (Isolate), the next immediate steps are Step 3 (Disable System Restore) and Step 4a (Update anti-malware signatures).
Following the standardized sequence prevents reinfection and ensures effective scanning.
2
Disable System Restore
System restore points are cleared so backups do not archive malicious payloads.
If malware is archived in a restore point, restoring the system later would reintroduce the threat.
3
Obtain updated malware signatures while isolated
Download definitions on a clean device and transfer them out-of-band via removable USB media.
The infected machine remains isolated from the network to prevent malware propagation while ensuring the anti-malware tool has current detection signatures.

Anahtar Kavram

CompTIA 7-Step Malware Removal Procedure - System Restore Disabling and Out-of-Band Definition Updates
Bu soruyu puanla