nerdexam
CompTIA

220-1102 · Question #107

A user calls the help desk to report potential malware on a computer. The anomalous activity began after the user clicked a link to a free gift card in a recent email The technician asks the user to…

The correct answer is D. Instruct the user to disconnect the Ethernet connection to the corporate network. The immediate next step for a suspected malware infection is to isolate the affected machine from the network. Disconnecting the Ethernet connection prevents the malware from spreading to other systems or exfiltrating data.

Security

Question

A user calls the help desk to report potential malware on a computer. The anomalous activity began after the user clicked a link to a free gift card in a recent email The technician asks the user to describe any unusual activity, such as slow performance, excessive pop-ups, and browser redirections. Which of the following should the technician do NEXT?

Options

  • AAdvise the user to run a complete system scan using the OS anti-malware application
  • BGuide the user to reboot the machine into safe mode and verify whether the anomalous activities
  • CHave the user check for recently installed applications and outline those installed since the link in
  • DInstruct the user to disconnect the Ethernet connection to the corporate network.

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    16% (5)
  • C
    6% (2)
  • D
    74% (23)

Why each option

The immediate next step for a suspected malware infection is to isolate the affected machine from the network. Disconnecting the Ethernet connection prevents the malware from spreading to other systems or exfiltrating data.

AAdvise the user to run a complete system scan using the OS anti-malware application

Running a scan is an important step in malware remediation, but network isolation should occur first to prevent further harm.

BGuide the user to reboot the machine into safe mode and verify whether the anomalous activities

Rebooting into safe mode is a troubleshooting step to remove malware, but network isolation must precede it to contain the threat.

CHave the user check for recently installed applications and outline those installed since the link in

Checking for recently installed applications is part of the investigation process but comes after isolating the threat to prevent further damage.

DInstruct the user to disconnect the Ethernet connection to the corporate network.Correct

The most critical immediate action when suspected malware is present is to isolate the infected system from the network, preventing the malware from spreading to other systems, accessing network resources, or exfiltrating sensitive data. Disconnecting the Ethernet cable effectively achieves this isolation.

Concept tested: Malware incident response - containment

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/antivirus-windows-10

Topics

#Malware#Incident Response#Containment#Network Security

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice