CompTIA A+ Core 2 (220-1202)Software TroubleshootingHard

A technician has finished remediating a malware infection, verified the system is clean, and updated the anti-malware definitions. Which of the following should the technician perform NEXT, according to the best-practice malware removal procedure, before returning the workstation to the user?

  1. AImmediately reconnect the system to the network without further testing
  2. BDisable the Windows Firewall to test connectivity
  3. CSchedule future scans and enable System Restore, creating a new restore point
  4. DReinstall the operating system as a precaution
Show answer & explanation

Correct answer: C. Schedule future scans and enable System Restore, creating a new restore point

After remediation is complete, best practice dictates scheduling future scans and updates, then re-enabling System Restore and creating a fresh restore point, before finally educating the user and returning the machine to service.

Why the other options are wrong

  • A. Reconnecting without completing the remaining steps skips important safeguards against reinfection.
  • B. Disabling the firewall would reduce security and is never part of this process.
  • D. A full OS reinstall is unnecessary once the system has already been verified clean.

Post-Remediation Malware Steps

After malware remediation and verification, technicians should schedule ongoing scans, re-enable System Restore with a new restore point, and educate the user before returning the device to service.

  • Scheduling scans ensures ongoing protection against reinfection.
  • A new restore point captures the clean system state.
  • User education is the final step to prevent future infections.

Memory trick: 'Clean, Schedule, Snapshot, Teach'

More Software Troubleshooting questions