Soru

Zorluk: ZorMalware Symptoms and Standard Removal Procedures

A network administrator monitoring a high-availability telemetry console at a commercial building management facility notices pop-up warnings indicating active file encryption and unauthorized background network socket activity. The administrator immediately unplugs the Ethernet cable and disables wireless adapters to isolate the system. According to the CompTIA 7-step malware removal procedure, which of the following actions should the administrator perform NEXT?

  1. Disable System Protection to prevent malicious executables from being saved in volume shadow copies.Cevap
  2. B
    Boot the system into Safe Mode and execute an updated antimalware remediation scan.
  3. C
    Inspect Device Manager to roll back network adapter driver updates causing socket anomalies.
  4. D
    Run sfc /scannow from an elevated command prompt to repair corrupted system executables.

Cevap

The administrator should disable System Protection (System Restore) to prevent malicious files from being preserved in system backup points prior to remediation.
According to CompTIA's official 7-step malware removal workflow, after identifying symptoms (Step 1) and isolating the system from the network (Step 2), the technician must disable System Restore/System Protection (Step 3). Disabling System Restore deletes existing restore points so infected files cannot be restored accidentally or re-triggered automatically.

Adım Adım Çözüm

1
Identify malware symptoms.
Malware activity confirmed via unauthorized encryption alerts and socket activity.
Establishes the presence and scope of the malware threat.
2
Isolate the infected system.
Network interfaces disconnected.
Prevents lateral movement across the internal network.
3
Disable System Restore / System Protection.
Existing restore points and volume snapshots containing malicious code are purged/disabled.
Ensures that malware cannot persist or trigger reinfection through system recovery points.

Anahtar Kavram

CompTIA 7-step malware removal process: 1. Identify symptoms, 2. Isolate system, 3. Disable System Restore, 4. Remediate infected systems, 5. Schedule scans and updates, 6. Enable System Restore and create restore point, 7. Educate end user.
Bu soruyu puanla