Soru

Zorluk: OrtaMalware Detection, Removal, and Prevention

A systems administrator at a financial services firm is troubleshooting a workstation infected with a spyware Trojan. The administrator has already identified the malware symptoms and successfully isolated the system from the local network. Which TWO of the following steps should the administrator perform next before initiating scans and removing the infection? (Select TWO.)

  1. Disable Windows System RestoreCevap
  2. Update anti-malware signature definition filesCevap
  3. C
    Re-enable System Restore and create a new restore point
  4. D
    Provide end-user awareness training regarding suspicious file downloads

Cevap

The administrator should disable Windows System Restore and update anti-malware signature definition files.
Following quarantine, the technician must disable System Restore to ensure that infected system files are not backed up or preserved in system restore points. Immediately after, updating anti-malware signatures ensures that the security engine possesses the newest threat definitions before running full remediation scans.

Adım Adım Çözüm

1
Review current progress within the CompTIA 7-step malware remediation framework
Step 1 (Identify malware symptoms) and Step 2 (Quarantine the infected system) are already complete.
Evaluating current status identifies which sequential actions must be taken prior to remediation.
2
Determine the mandatory actions prior to active system scanning and cleaning
Step 3 requires disabling System Restore, and Step 4a requires updating anti-malware software/signatures.
Disabling restore points prevents infected files from being saved in system restore archives, while updated signatures ensure accurate threat detection.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process
Bu soruyu puanla