nerdexam
CompTIA

220-1102 · Question #407

A technician successfully removed malicious software from an infected computer after running updates and scheduled scans to mitigate future risks. Which of the following should the technician do next?

The correct answer is A. Educate the end user on best practices for security. After successfully remediating a malware infection and implementing preventative measures like updates and scheduled scans, the next critical step is to educate the end user on security best practices. This helps prevent future infections by addressing potential human factors…

Security

Question

A technician successfully removed malicious software from an infected computer after running updates and scheduled scans to mitigate future risks. Which of the following should the technician do next?

Options

  • AEducate the end user on best practices for security.
  • BQuarantine the host in the antivirus system.
  • CInvestigate how the system was infected with malware.
  • DCreate a system restore point.

How the community answered

(36 responses)
  • A
    75% (27)
  • B
    3% (1)
  • C
    17% (6)
  • D
    6% (2)

Why each option

After successfully remediating a malware infection and implementing preventative measures like updates and scheduled scans, the next critical step is to educate the end user on security best practices. This helps prevent future infections by addressing potential human factors that contributed to the incident.

AEducate the end user on best practices for security.Correct

User education on security best practices is a vital preventative measure that addresses human factors which often contribute to malware infections, helping to prevent recurrence after a system has been cleaned.

BQuarantine the host in the antivirus system.

The host should have already been isolated or quarantined during the initial phases of incident response, not after the malware has been successfully removed.

CInvestigate how the system was infected with malware.

Investigating the root cause of the infection is an important step, but often occurs before or concurrently with remediation, or as part of a deeper post-incident analysis, but user education is a direct and immediate action to prevent re-infection.

DCreate a system restore point.

Creating a system restore point is a good general practice for system recovery, but it is not the immediate next step specifically related to preventing future malware infections after remediation and updates.

Concept tested: Incident response - post-incident activities and prevention

Source: https://learn.microsoft.com/compliance/assurance/assurance-incident-management

Topics

#Malware removal#Security best practices#User education#Post-remediation

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice