CompTIA A+ Core 2 (220-1202)Software TroubleshootingMedium

A technician has completed malware remediation on a workstation: the infection was verified, the system was quarantined, System Restore was disabled and later re-enabled with a new restore point, and updated anti-malware software removed all threats after a full scan. According to CompTIA best practice, which FINAL step should the technician perform before closing the ticket?

  1. AReformat the drive and reinstall the operating system
  2. BDisable the workstation's network adapter permanently
  3. CDelete all restore points to remove any trace of the infection
  4. DEducate the end user on safe computing practices to prevent reinfection
Show answer & explanation

Correct answer: D. Educate the end user on safe computing practices to prevent reinfection

The CompTIA malware removal best-practice procedure ends with educating the end user (e.g., on phishing awareness, safe browsing, and update hygiene) to help prevent future infections. Deleting restore points or reformatting are not required once remediation is verified successful.

Why the other options are wrong

  • A. Reformatting is unnecessary once remediation is confirmed successful.
  • B. Permanently disabling networking makes the machine unusable and isn't part of the procedure.
  • C. Restore points were already recreated after remediation; deleting them isn't a required step.

Educate the End User (Malware Removal)

The final step of the malware removal best-practice procedure, where the technician informs the user about safe practices to prevent future infections.

  • Last of the 7 documented remediation steps
  • Covers phishing, safe browsing, updates
  • Reduces likelihood of reinfection

Memory trick: 'Investigate, Quarantine, Disable, Remediate, Schedule, Enable, Educate' — IQDRSEE ends in teaching.

More Software Troubleshooting questions