CompTIA A+ Core 2 (220-1202)SecurityMedium
A technician confirms that a workstation is infected with ransomware. According to standard malware removal best practices, which step should be performed immediately after identifying the infection and before remediation?
- AQuarantine the infected system
- BSchedule automatic future scans
- CEnable System Restore
- DEducate the end user on prevention
Show answer & explanationAnswer & explanation
Correct answer: A. Quarantine the infected system
After confirming an infection, the infected system must be quarantined (disconnected from the network) to prevent the malware from spreading before remediation steps like disabling System Restore and running removal tools are performed.
Why the other options are wrong
- B. Scheduling future scans occurs after remediation, not immediately after identification.
- C. System Restore should be disabled during remediation and re-enabled only after cleanup, not enabled at this stage.
- D. User education happens at the end of the process, after the threat is resolved.
Malware Removal Best Practices
A standardized sequence for handling malware: identify, quarantine, disable System Restore, remediate, schedule scans/updates, re-enable System Restore, and educate the user.
- Quarantine isolates the system from the network
- System Restore is disabled to avoid restoring infected files
- End-user education is the final step
Memory trick: 'I Quit Dirty Rats, Schedule Regular Enforcement' = Identify, Quarantine, Disable Restore, Remediate, Schedule, Re-enable, Educate.