nerdexam
CompTIA

220-1002 · Question #160

A user reports malware activity on an isolated workstation used for testing. It is running an end-of- life OS, and a USB drive is the only method used to transfer files. After removing the malware…

The correct answer is D. Update the local antivirus and set it to scan automatically every evening. The malware returned despite removing it and providing a clean USB drive, which means the malware was not fully eradicated from the system - likely because the antivirus definitions were outdated and could not detect all variants or remnants. On an end-of-life OS with a…

Hardware and network troubleshooting

Question

A user reports malware activity on an isolated workstation used for testing. It is running an end-of- life OS, and a USB drive is the only method used to transfer files. After removing the malware and replacing the USB drive with a brand new one, the technician gives the approval to use the equipment. The next day the user reports the same malware activity is present after powering on the system. Which of the following did the technician forget to do to prevent reinfection?

Options

  • AConnect to the network and update the OS with the latest security patches
  • BScan and clean the USB device used to transfer data from the equipment
  • CDisable System restore and remove all restore points from the system
  • DUpdate the local antivirus and set it to scan automatically every evening

How the community answered

(46 responses)
  • A
    13% (6)
  • B
    30% (14)
  • C
    7% (3)
  • D
    50% (23)

Explanation

The malware returned despite removing it and providing a clean USB drive, which means the malware was not fully eradicated from the system - likely because the antivirus definitions were outdated and could not detect all variants or remnants. On an end-of-life OS with a potentially stale AV database, the initial removal may have been incomplete. Updating the AV definitions would give it current signatures to detect and remove the malware thoroughly. Setting it to scan automatically every evening would catch any reinfection attempts proactively. Connecting to the network is impossible since it is isolated. The new USB drive eliminates USB as the reinfection vector. Without current AV definitions and automated scanning, residual malware can re-activate on startup.

Topics

#malware reinfection#antivirus updates#end-of-life OS#USB transfer security

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice