220-1102 · Question #107
A user calls the help desk to report potential malware on a computer. The anomalous activity began after the user clicked a link to a free gift card in a recent email The technician asks the user to…
The correct answer is D. Instruct the user to disconnect the Ethernet connection to the corporate network. The immediate next step for a suspected malware infection is to isolate the affected machine from the network. Disconnecting the Ethernet connection prevents the malware from spreading to other systems or exfiltrating data.
Question
A user calls the help desk to report potential malware on a computer. The anomalous activity began after the user clicked a link to a free gift card in a recent email The technician asks the user to describe any unusual activity, such as slow performance, excessive pop-ups, and browser redirections. Which of the following should the technician do NEXT?
Options
- AAdvise the user to run a complete system scan using the OS anti-malware application
- BGuide the user to reboot the machine into safe mode and verify whether the anomalous activities
- CHave the user check for recently installed applications and outline those installed since the link in
- DInstruct the user to disconnect the Ethernet connection to the corporate network.
How the community answered
(31 responses)- A3% (1)
- B16% (5)
- C6% (2)
- D74% (23)
Why each option
The immediate next step for a suspected malware infection is to isolate the affected machine from the network. Disconnecting the Ethernet connection prevents the malware from spreading to other systems or exfiltrating data.
Running a scan is an important step in malware remediation, but network isolation should occur first to prevent further harm.
Rebooting into safe mode is a troubleshooting step to remove malware, but network isolation must precede it to contain the threat.
Checking for recently installed applications is part of the investigation process but comes after isolating the threat to prevent further damage.
The most critical immediate action when suspected malware is present is to isolate the infected system from the network, preventing the malware from spreading to other systems, accessing network resources, or exfiltrating sensitive data. Disconnecting the Ethernet cable effectively achieves this isolation.
Concept tested: Malware incident response - containment
Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-antivirus/antivirus-windows-10
Topics
Community Discussion
No community discussion yet for this question.