ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 534 - 220-1102 discussion

Report
Export

A user reports that an air-gapped computer may have been infected with a virus after the user transferred files from a USB drive. The technician runs a computer scan with Windows Defender but does not find an infection. Which of the following actions should the technician take next? (Select two).

A.
Examine the event logs.
Answers
A.
Examine the event logs.
B.
Connect to the network.
Answers
B.
Connect to the network.
C.
Document the findings.
Answers
C.
Document the findings.
D.
Update the definitions.
Answers
D.
Update the definitions.
E.
Reimage the computer.
Answers
E.
Reimage the computer.
F.
Enable the firewall.
Answers
F.
Enable the firewall.
Suggested answer: A, D

Explanation:

When dealing with a suspected virus infection on an air-gapped computer, after an initial scan with Windows Defender shows no infection, the next steps should include examining the event logs to look for suspicious activity and updating the virus definitions for a more thorough scan. Event logs can provide insights into system changes and potential malicious activities, while updated definitions ensure the antivirus software can detect the latest threats. Connecting to the network or enabling the firewall might not be appropriate due to the risk of spreading the infection, and re-imaging the computer or documenting the findings would be subsequent steps if the initial actions don't resolve the issue.

Reference: Official CompTIA A+ Core 1 and Core 2 Student Guide.

asked 02/10/2024
Ryan Lee
27 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first