220-1002 · Question #245
Joe, a technician, receives notification that a share for production data files on the network is encrypted. Joe suspects a crypto virus is active. He checks the rights of the network share to see…
The correct answer is B. Scan and remove the malware from the infected system. Removing the infected machine from the network isolates the threat but does not remediate it. The immediate next step in malware remediation is to scan the system and remove the malware to fully clean it. Educating the user, creating restore points, and scheduling future scans…
Question
Joe, a technician, receives notification that a share for production data files on the network is encrypted. Joe suspects a crypto virus is active. He checks the rights of the network share to see which departments have access. He then searches the user directories of those departmental users who are looking for encrypted files. He narrows his search to a single user's computer. Once the suspected source of the virus is discovered and removed from the network, which of the following should Joe do NEXT?
Options
- AEducate the end user on safe browsing and email habits.
- BScan and remove the malware from the infected system.
- CCreate a system restore point and reboot the system.
- DSchedule antivirus scans and perform Windows updates.
How the community answered
(24 responses)- A8% (2)
- B83% (20)
- C4% (1)
- D4% (1)
Explanation
Removing the infected machine from the network isolates the threat but does not remediate it. The immediate next step in malware remediation is to scan the system and remove the malware to fully clean it. Educating the user, creating restore points, and scheduling future scans all come after the system has been confirmed clean. Performing remediation before user education ensures the threat is eliminated before the machine is returned to service.
Topics
Community Discussion
No community discussion yet for this question.