220-1002 · Question #632
A technician is removing malware from a workstation. The malware was installed via a phishing attack, which was initiated from a link that was included in an email. Which of the following should the…
The correct answer is C. Restore the system using the last known-good configuration from the recovery console. E. Educate the user on verifying email links by hovering over them before clicking. NOTE: The listed correct answer (C, E) is questionable. 'Last known-good configuration' (C) is a legacy Windows XP/Vista feature that no longer exists as a recovery option in Windows 10/11, making it an unlikely correct answer for a current exam scenario. The two most…
Question
A technician is removing malware from a workstation. The malware was installed via a phishing attack, which was initiated from a link that was included in an email. Which of the following should the technician do to address this issue? (Choose two.)
Options
- AEnsure the anti-rootkit utility is up to date and run it to remove the threat.
- BUpdate the host firewall to block port 80 on the workstation.
- CRestore the system using the last known-good configuration from the recovery console.
- DEnsure antivirus is up to date and install the latest patches.
- EEducate the user on verifying email links by hovering over them before clicking.
- FEnsure endpoint protection is up to date and run the utility to remove the threat.
How the community answered
(34 responses)- A3% (1)
- B6% (2)
- C79% (27)
- D12% (4)
Explanation
NOTE: The listed correct answer (C, E) is questionable. 'Last known-good configuration' (C) is a legacy Windows XP/Vista feature that no longer exists as a recovery option in Windows 10/11, making it an unlikely correct answer for a current exam scenario. The two most appropriate actions for removing phishing-delivered malware are: (D) Ensure antivirus is up to date and install the latest patches - updated antivirus detects and removes the malware, and patches close the vulnerabilities the malware may exploit; and (E) Educate the user on verifying email links by hovering before clicking - this addresses the root cause (user behavior) and prevents recurrence. Option F (update endpoint protection and run it) is nearly identical to D and is also a strong answer. For CompTIA A+ exam purposes, if the listed answer is C and E, E is clearly correct, and C may reflect an outdated exam objective; candidates should also know D and F are the operationally correct remediation steps.
Topics
Community Discussion
No community discussion yet for this question.