nerdexam
CompTIA

220-1002 · Question #169

A technician has been dispatched to resolve a malware problem on a user's workstation. The antivirus program discovered several hundred potential malware items on the workstation and removed them…

The correct answer is D. Educate the user on safe browsing practices. Following CompTIA's malware removal best practices, after remediation steps are complete (scanning, removing malware, scheduling ongoing scans, and creating a clean restore point), the final step is to educate the end user. Since hundreds of malware items were found, user…

Hardware and network troubleshooting

Question

A technician has been dispatched to resolve a malware problem on a user's workstation. The antivirus program discovered several hundred potential malware items on the workstation and removed them successfully. The technician decides to schedule daily scans on the system, enables System Restore, and creates a restore point. Which of the following should the technician do NEXT?

Options

  • ARun the scan again to ensure all malware has been removed
  • BQuarantine the infected workstation from the network
  • CInstall all of the latest Windows Updates to patch the system
  • DEducate the user on safe browsing practices

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    7% (2)
  • C
    7% (2)
  • D
    82% (23)

Explanation

Following CompTIA's malware removal best practices, after remediation steps are complete (scanning, removing malware, scheduling ongoing scans, and creating a clean restore point), the final step is to educate the end user. Since hundreds of malware items were found, user behavior (e.g., clicking suspicious links, downloading unsafe files) is likely the root cause. Educating the user helps prevent reinfection. The other steps - running the scan again, quarantining the workstation, and installing updates - are valid steps but should occur earlier in the remediation process, before the restore point is created.

Topics

#malware removal#incident response#end-user education#security policy

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice