nerdexam
CompTIA

220-1002 · Question #556

A recent ransomware attack caused several datasets to be inaccessible. Security technicians were able to mitigate any additional attacks and remove any unauthorized software. Which of the following…

The correct answer is A. Run an antivirus tool. After a ransomware attack where unauthorized software has been removed, the CompTIA A+ malware remediation process requires running a full antivirus/anti-malware scan to verify the system is completely clean before attempting data recovery. Restoring from backup (D) before…

Hardware and network troubleshooting

Question

A recent ransomware attack caused several datasets to be inaccessible. Security technicians were able to mitigate any additional attacks and remove any unauthorized software. Which of the following should the technicians do NEXT?

Options

  • ARun an antivirus tool.
  • BBoot to the Recovery Console
  • CUpdate the software firewall
  • DRestore from backup.

How the community answered

(44 responses)
  • A
    82% (36)
  • B
    5% (2)
  • C
    2% (1)
  • D
    11% (5)

Explanation

After a ransomware attack where unauthorized software has been removed, the CompTIA A+ malware remediation process requires running a full antivirus/anti-malware scan to verify the system is completely clean before attempting data recovery. Restoring from backup (D) before confirming the system is fully clean risks re-infecting the restored data or allowing residual malware to re-encrypt the files. Running the AV tool (A) serves as a verification step to ensure all malicious artifacts are gone, making it the correct next step. Updating the software firewall (C) is a preventative measure for the future, and booting to Recovery Console (B) is not relevant after malware removal.

Topics

#ransomware#incident response#malware removal#data recovery

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice