220-1102 · Question #493
A user reports that an air-gapped computer may have been infected with a virus after the user transferred files from a USB drive. The technician runs a computer scan with Windows Defender but does…
The correct answer is A. Examine the event logs C. Document the findings. After an initial scan of a potentially infected air-gapped system yields no results, the technician should next examine event logs for suspicious activity and document all findings.
Question
A user reports that an air-gapped computer may have been infected with a virus after the user transferred files from a USB drive. The technician runs a computer scan with Windows Defender but does not find an infection. Which of the following actions should the technician take next? (Choose two.)
Options
- AExamine the event logs
- BConnect to the network
- CDocument the findings
- DUpdate the definitions
- EReimage the computer
- FEnable the firewall
How the community answered
(32 responses)- A75% (24)
- B13% (4)
- D6% (2)
- E3% (1)
- F3% (1)
Why each option
After an initial scan of a potentially infected air-gapped system yields no results, the technician should next examine event logs for suspicious activity and document all findings.
Examining the event logs (e.g., Windows Event Viewer) is crucial because malware, even if undetected by an initial antivirus scan, often leaves traces of activity such as unusual login attempts, process creations, or system errors that can indicate compromise. This provides a deeper level of forensic analysis.
Connecting an air-gapped computer to the network would defeat its purpose of isolation and could potentially spread an undetected infection or expose the network to the supposedly infected machine.
Documenting the findings is a critical step in any troubleshooting and incident response process. It ensures a clear record of the problem, actions taken, and results, which is essential for future reference, compliance, and improving security policies.
Updating definitions on an air-gapped computer typically requires connecting it to a network or using an external medium, which could introduce risk or is not the immediate next step after a scan, especially if the current definitions are recent.
Reimaging the computer is a drastic step typically reserved for confirmed infections that cannot be remediated or for high-security environments, not for an initial "may have been infected" scenario without further evidence.
Enabling the firewall is a good security practice, but for an air-gapped system that is not connected to a network, its immediate impact on detecting or preventing an internal infection from a USB drive is minimal.
Concept tested: Incident response for air-gapped systems and malware investigation
Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-scan-options
Topics
Community Discussion
No community discussion yet for this question.