ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 750 - 220-1102 discussion

Report
Export

A technician received a notification about encrypted production data files and thinks active ransomware is on the network. The technician isolated and removed the suspicious system from the network. Which of the following steps should the technician take next?

A.

Schedule and perform an antivirus scan and system update

Answers
A.

Schedule and perform an antivirus scan and system update

B.

Educate the end user on internet usage

Answers
B.

Educate the end user on internet usage

C.

Perform a system scan to remove the malware

Answers
C.

Perform a system scan to remove the malware

D.

Create a system restore point

Answers
D.

Create a system restore point

Suggested answer: C

Explanation:

Detailed

The next step after isolating the system is to perform a system scan to remove the malware (Option C). Since ransomware is suspected, running a comprehensive malware scan can help identify and remove the malicious software. It is crucial to deal with the active threat before taking further actions.

Scheduling an antivirus scan and system update (Option A) may help, but the immediate concern is identifying and removing the ransomware.

Educating the end user (Option B) is important but should happen after the immediate threat is resolved.

Creating a system restore point (Option D) would not be useful at this point since the system is infected.

CompTIA A+ Core 2

Reference:

2.3 - Detect, remove, and prevent malware, including handling ransomware.

asked 27/10/2024
charles ratchagaraj
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first