220-1102 · Question #407
A technician successfully removed malicious software from an infected computer after running updates and scheduled scans to mitigate future risks. Which of the following should the technician do next?
The correct answer is A. Educate the end user on best practices for security. After successfully remediating a malware infection and implementing preventative measures like updates and scheduled scans, the next critical step is to educate the end user on security best practices. This helps prevent future infections by addressing potential human factors…
Question
A technician successfully removed malicious software from an infected computer after running updates and scheduled scans to mitigate future risks. Which of the following should the technician do next?
Options
- AEducate the end user on best practices for security.
- BQuarantine the host in the antivirus system.
- CInvestigate how the system was infected with malware.
- DCreate a system restore point.
How the community answered
(36 responses)- A75% (27)
- B3% (1)
- C17% (6)
- D6% (2)
Why each option
After successfully remediating a malware infection and implementing preventative measures like updates and scheduled scans, the next critical step is to educate the end user on security best practices. This helps prevent future infections by addressing potential human factors that contributed to the incident.
User education on security best practices is a vital preventative measure that addresses human factors which often contribute to malware infections, helping to prevent recurrence after a system has been cleaned.
The host should have already been isolated or quarantined during the initial phases of incident response, not after the malware has been successfully removed.
Investigating the root cause of the infection is an important step, but often occurs before or concurrently with remediation, or as part of a deeper post-incident analysis, but user education is a direct and immediate action to prevent re-infection.
Creating a system restore point is a good general practice for system recovery, but it is not the immediate next step specifically related to preventing future malware infections after remediation and updates.
Concept tested: Incident response - post-incident activities and prevention
Source: https://learn.microsoft.com/compliance/assurance/assurance-incident-management
Topics
Community Discussion
No community discussion yet for this question.