220-1002 · Question #794
A user's antivirus software is reporting several infections and prompting the user to pay full version to remove the threats. A technician notices the corporate approved antivirus software has not…
The correct answer is A. Connect the hard drive to another computer and reinstall the operating system. The scenario describes rogue/scareware malware - a fake antivirus that mimics legitimate security software and demands payment. Because the real corporate antivirus is outdated and the system is compromised, the operating environment can no longer be trusted to perform a clean…
Question
A user's antivirus software is reporting several infections and prompting the user to pay full version to remove the threats. A technician notices the corporate approved antivirus software has not been upgraded in months. Which of the following should the technician do NEXT to remove the threat?
Options
- AConnect the hard drive to another computer and reinstall the operating system.
- BRemove all lines that are not comment from the host file and set it to ready only.
- CPay for the upgrade to remove the threats and install an trusted antivirus.
- DPermission inheritance
How the community answered
(22 responses)- A82% (18)
- B9% (2)
- C5% (1)
- D5% (1)
Explanation
The scenario describes rogue/scareware malware - a fake antivirus that mimics legitimate security software and demands payment. Because the real corporate antivirus is outdated and the system is compromised, the operating environment can no longer be trusted to perform a clean removal. The safest remediation is to remove the drive, attach it to a known-clean machine to preserve data if needed, then wipe and reinstall the OS. Paying the ransom (C) funds criminals and does not guarantee removal. Editing the hosts file (B) is a partial mitigation, not a full remediation. Option D ('Permission inheritance') is not a malware removal action.
Topics
Community Discussion
No community discussion yet for this question.