nerdexam
CompTIA

220-1102 · Question #740

A computer has been infected with malware. Despite several attempts to remove the malware, the issue persists. Which of the following actions should the technician take next? (Choose two.)

The correct answer is A. Reimage the computer. C. Remove the computer from the network. If malware persists despite removal attempts, the critical next steps are to isolate the infected computer from the network to prevent further spread and then reimage it to ensure complete eradication of the threat.

Security

Question

A computer has been infected with malware. Despite several attempts to remove the malware, the issue persists. Which of the following actions should the technician take next? (Choose two.)

Options

  • AReimage the computer.
  • BRestore the computer using the last known-good backup.
  • CRemove the computer from the network.
  • DPut the computer in safe mode.
  • EVerify the file consistency.
  • FEnable the system firewall.

How the community answered

(25 responses)
  • A
    84% (21)
  • B
    4% (1)
  • D
    8% (2)
  • E
    4% (1)

Why each option

If malware persists despite removal attempts, the critical next steps are to isolate the infected computer from the network to prevent further spread and then reimage it to ensure complete eradication of the threat.

AReimage the computer.Correct

Reimaging the computer involves completely wiping the existing operating system and reinstalling it from scratch, which is the most definitive way to ensure all malware is removed when other attempts have failed.

BRestore the computer using the last known-good backup.

Restoring from a last known-good backup is an option, but reimaging offers a more certain path to a clean state when removal attempts have already failed and the exact infection time or backup integrity is uncertain.

CRemove the computer from the network.Correct

Removing the computer from the network is crucial to prevent the malware from spreading to other systems or exfiltrating data, isolating the threat while remediation efforts are underway.

DPut the computer in safe mode.

Putting the computer in safe mode is a common initial step for malware removal, but the question states 'several attempts to remove the malware' have already failed, implying safe mode was likely already tried or ineffective.

EVerify the file consistency.

Verifying file consistency is a troubleshooting step, but it doesn't directly remove malware; malware can masquerade as legitimate files or corrupt system files, making simple consistency checks insufficient for eradication.

FEnable the system firewall.

Enabling the system firewall is a preventative measure or a component of ongoing security, but it does not remove existing malware that has already bypassed initial defenses.

Concept tested: Malware remediation and incident response

Source: https://www.comptia.org/blog/how-to-remove-malware-from-a-computer

Topics

#Malware removal#System re-imaging#Network security#Troubleshooting steps

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice