ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 436 - 220-1102 discussion

Report
Export

Antivirus software indicates that a workstation is infected with ransomware that cannot be quarantined. Which of the following should be performed first to prevent further damage to the host and other systems?

A.
Turn off the machine.
Answers
A.
Turn off the machine.
B.
Run a full antivirus scan.
Answers
B.
Run a full antivirus scan.
C.
Remove the LAN card.
Answers
C.
Remove the LAN card.
D.
Install a different endpoint solution.
Answers
D.
Install a different endpoint solution.
Suggested answer: A

Explanation:

Turning off the machine is the first and most urgent step to prevent further damage to the host and other systems. Ransomware can encrypt files, steal data, and spread to other devices on the network if the infected machine remains online.Turning off the machine will stop the ransomware process and isolate the machine from the network12. The other options are either ineffective or risky. Running a full antivirus scan may not detect or remove the ransomware, especially if it is a new or unknown variant. Removing the LAN card may disconnect the machine from the network, but it will not stop the ransomware from encrypting or deleting files on the local drive. Installing a different endpoint solution may not be possible or helpful if the ransomware has already compromised the system or blocked the installation.

asked 02/10/2024
Jason Wang
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first