CompTIA A+ Core 2 (220-1202)Software TroubleshootingHard
A technician has finished remediating a malware infection, verified the system is clean, and updated the anti-malware definitions. Which of the following should the technician perform NEXT, according to the best-practice malware removal procedure, before returning the workstation to the user?
- AImmediately reconnect the system to the network without further testing
- BDisable the Windows Firewall to test connectivity
- CSchedule future scans and enable System Restore, creating a new restore point
- DReinstall the operating system as a precaution
Show answer & explanationAnswer & explanation
Correct answer: C. Schedule future scans and enable System Restore, creating a new restore point
After remediation is complete, best practice dictates scheduling future scans and updates, then re-enabling System Restore and creating a fresh restore point, before finally educating the user and returning the machine to service.
Why the other options are wrong
- A. Reconnecting without completing the remaining steps skips important safeguards against reinfection.
- B. Disabling the firewall would reduce security and is never part of this process.
- D. A full OS reinstall is unnecessary once the system has already been verified clean.
Post-Remediation Malware Steps
After malware remediation and verification, technicians should schedule ongoing scans, re-enable System Restore with a new restore point, and educate the user before returning the device to service.
- Scheduling scans ensures ongoing protection against reinfection.
- A new restore point captures the clean system state.
- User education is the final step to prevent future infections.
Memory trick: 'Clean, Schedule, Snapshot, Teach'