nerdexam
CompTIA

220-1102 · Question #682

A user's workstation was infected with a newly discovered virus that the AV system detected. After a full virus scan and a workstation reboot, the virus is still present in the OS. Which of the…

The correct answer is B. Use bootable antivirus media to scan the system. When a virus persists after standard AV scans and reboots, using bootable antivirus media is often necessary to scan and remove the malware before the operating system loads and activates the virus.

Security

Question

A user's workstation was infected with a newly discovered virus that the AV system detected. After a full virus scan and a workstation reboot, the virus is still present in the OS. Which of the following actions should the user take to remove the virus?

Options

  • AEnable the system firewall.
  • BUse bootable antivirus media to scan the system.
  • CDownload software designed to specifically target the virus.
  • DRun the operating system update process.

How the community answered

(16 responses)
  • A
    13% (2)
  • B
    75% (12)
  • C
    6% (1)
  • D
    6% (1)

Why each option

When a virus persists after standard AV scans and reboots, using bootable antivirus media is often necessary to scan and remove the malware before the operating system loads and activates the virus.

AEnable the system firewall.

Enabling the system firewall can prevent network propagation but will not remove an existing virus that has already infected the operating system.

BUse bootable antivirus media to scan the system.Correct

Bootable antivirus media allows the system to be scanned for malware from a clean environment, outside of the infected operating system. This method is highly effective for removing persistent or rootkit-type viruses that might evade detection or removal by an antivirus running within the compromised OS.

CDownload software designed to specifically target the virus.

Downloading software from an infected system is risky, as the malware could interfere with the download or installation, or even mask the true nature of the downloaded software; furthermore, it might not be effective if the malware is active.

DRun the operating system update process.

Running operating system updates patches vulnerabilities but typically does not remove active malware already present on the system.

Concept tested: Malware removal techniques - persistent infections

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/intelligence/advanced-troubleshooting-for-microsoft-defender-antivirus

Topics

#Malware removal#Antivirus#Bootable media#Virus infection

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice