220-1102 · Question #555
A technician is troubleshooting a PC because the user has reported strange pop-up windows and computer performance issues. Which of the following actions should the technician take next?
The correct answer is A. Isolate the machine from the network. When a PC exhibits symptoms of malware, the immediate next step is to isolate it from the network to prevent the potential spread of infection.
Question
A technician is troubleshooting a PC because the user has reported strange pop-up windows and computer performance issues. Which of the following actions should the technician take next?
Options
- AIsolate the machine from the network.
- BScan the system for hidden files.
- CDisable unused ports.
- DInstall antivirus software.
- EReconfigure the firewall.
How the community answered
(66 responses)- A73% (48)
- B15% (10)
- C2% (1)
- D3% (2)
- E8% (5)
Why each option
When a PC exhibits symptoms of malware, the immediate next step is to isolate it from the network to prevent the potential spread of infection.
Isolating the machine from the network prevents the potential malware from spreading to other systems or exfiltrating data, containing the threat while further remediation occurs. This is a critical first step in a malware response plan to limit damage and facilitate safe investigation.
Scanning for hidden files is a diagnostic step performed after isolation, but not the immediate next step to contain the threat.
Disabling unused ports is a preventative hardening measure, not an immediate troubleshooting step for an active infection.
Installing antivirus software might be part of remediation, but if the system is already infected, installing new software while connected to the network could potentially put other systems at risk or be compromised by the existing malware.
Reconfiguring the firewall might be part of hardening after remediation, but it's not the immediate next step to contain an active infection.
Concept tested: Malware incident response - containment
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/respond-file-operations?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.