nerdexam
CompTIA

CS0-003 · Question #570

A security analyst identifies a device on which different malware was detected multiple times, even after the systems were scanned and cleaned several times. Which of the following actions would be…

The correct answer is B. Replace the hard drive and reimage the device. If malware persists after multiple cleanings, the most effective action is to reimage the device from a known good baseline and replace the hard drive if there's suspicion of low-level or boot- sector infection. This ensures complete removal of any hidden or persistent malware.

Submitted by olafpl· Mar 6, 2026Incident Response and Management

Question

A security analyst identifies a device on which different malware was detected multiple times, even after the systems were scanned and cleaned several times. Which of the following actions would be most effective to ensure the device does not have residual malware?

Options

  • AUpdate the device and scan offline in safe mode.
  • BReplace the hard drive and reimage the device.
  • CUpgrade the device to the latest OS version.
  • DDownload a secondary scanner and rescan the device.

How the community answered

(57 responses)
  • A
    5% (3)
  • B
    67% (38)
  • C
    19% (11)
  • D
    9% (5)

Explanation

If malware persists after multiple cleanings, the most effective action is to reimage the device from a known good baseline and replace the hard drive if there's suspicion of low-level or boot- sector infection. This ensures complete removal of any hidden or persistent malware.

Topics

#Malware remediation#Persistent threats#Reimaging#Hard drive replacement

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice