CompTIA A+ Core 2 (220-1202)Software TroubleshootingMedium

A technician confirms that a workstation is infected with malware after a user reported unusual pop-ups and slow performance. According to malware removal best practices, which of the following should the technician do immediately after investigating and verifying the malware symptoms?

  1. AEducate the end user
  2. BDisable System Restore
  3. CQuarantine the infected system by disconnecting it from the network
  4. DSchedule automatic scans
Show answer & explanation

Correct answer: C. Quarantine the infected system by disconnecting it from the network

After confirming an infection, the next best-practice step is to quarantine the system by isolating it from the network to prevent the malware from spreading to other devices before remediation begins.

Why the other options are wrong

  • A. Educating the user is the final step, after the system is confirmed clean.
  • B. Disabling System Restore comes after quarantine, once remediation is about to begin.
  • D. Scheduling scans happens after the system has been remediated, not before.

Malware Removal Best Practices

CompTIA's seven-step process for safely identifying and removing malware from a system while preventing reinfection.

  • Quarantine occurs immediately after verifying symptoms.
  • System Restore is disabled before remediation to avoid reinfection via restore points.
  • The process ends with user education to prevent recurrence.

Memory trick: 'Investigate, Isolate, then Eradicate'

More Software Troubleshooting questions