exam questions

Exam 220-1002 All Questions

View all questions & answers for the 220-1002 exam

Exam 220-1002 topic 1 question 178 discussion

Actual exam question from CompTIA's 220-1002
Question #: 178
Topic #: 1
[All 220-1002 Questions]

Joe, a technician, receives notification that a share for production data files on the network is encrypted. Joe suspects a crypto virus is active. He checks the rights of the network share to see which departments have access. He then searches the user directories of those departmental users who are looking for encrypted files. He narrows his search to a single user's computer.
Once the suspected source of the virus is discovered and removed from the network, which of the following should Joe do NEXT?

  • A. Educate the end user on safe browsing and email habits.
  • B. Scan and remove the malware from the infected system.
  • C. Create a system restore point and reboot the system.
  • D. Schedule antivirus scans and perform Windows updates.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JasonSignupHappy
Highly Voted 4 years, 2 months ago
Based on what I expect from this site, I would have expected "take the infected PC on a date, get it drunk and convince it to behave from now on" to not only BE an option, but selected AS THE CORRECT ANSWER
upvoted 21 times
...
MelvinJohn
Highly Voted 4 years, 5 months ago
[The “source (computer) of the virus was removed from the network” (quarantined) – what’s next?] B. Scan and remove the malware from the infected system. [The actual next step, “Disable System Restore” is missing from the answers, but the next step after that is “Remediate” (remove the infection). The 7 Steps of Malware Removal (IQDRSEE): {remember with: Eye Q Doctor See} 1 - Identify and research malware symptoms 2 - Quarantine infected systems (isolate it) 3 - Disable System Restore (to prevent any new restore points) 4 - Remediate infected systems (update antimalware software/scan and use removal techniques) 5 - Schedule scans and run updates 6 - Enable system restore and create restore point 7 - Educate the user
upvoted 6 times
cpaljchc
2 years, 5 months ago
"Once the suspected source of the virus is discovered and 'removed' from the network" Isn't that D is the correct answer from the above sentence.
upvoted 1 times
...
...
abxa
Most Recent 2 years, 10 months ago
Selected Answer: B
This question is about whether you know the steps to remove malware in the 1002 objectives. So it says the system has been removed from the network aka quarantined (step 2 Quarantine). There's no objection to disable system restore (step 3) so I guess it's not a windows system, the next step is to update the antivirus software, but that's not included so maybe that's done automatically or it's a zero-day and you're using a tool to remove it, whatever, the only next option left remaining is scan and remove. The other options are clearly next after removing.
upvoted 1 times
...
ElPato80
3 years, 1 month ago
The computer was removed from the NETWORK. Not the virus getting removed from the system. So once the computer has been Quarantined aka removed from the network to prevent the malware spreading, then we choose B which is about removing the malware off the infected system,
upvoted 3 times
...
SamuelNascimento
3 years, 2 months ago
When the inevitable happens and either your computer or one of your user’s computers gets infected by malware such as a computer virus, you need to follow certain steps to stop the problem from spreading and get the computer back up safely into service. The 1002 exam outlines the following multistep process as the best practice procedures for malware removal: 1. Identify and research malware symptoms. 2. Quarantine the infected systems. 3. Disable System Restore (in Windows). 4. Remediate the infected systems. A. Update the anti-malware software. B. Scan and use removal techniques (Safe Mode, Preinstallation Environment). 5. Schedule scans and run updates. 6. Enable System Restore and create a restore point (in Windows). 7. Educate the end user.
upvoted 1 times
...
TripeV
3 years, 3 months ago
A is the answer. They said the suspected source of the virus is discovered and removed from the network. After removing the affected pc, the next step is Scan and remove the malware from the infected system.
upvoted 1 times
ElPato80
3 years, 1 month ago
A is educate the user. The answer you are talking about is B.
upvoted 1 times
...
...
adeshtall
3 years, 6 months ago
why scan and remove when he has already "Once the suspected source of the virus is discovered and removed from the network" The virus have been removed we are told why you ask then to remove . It need to be D.
upvoted 2 times
DoggyStyle
3 years, 6 months ago
No, the "source of the virus" is a computer on the network. So, the computer is then removed from the network. Next step would be to scan, etc. (i.e. B).
upvoted 2 times
...
ZioPier
1 year, 11 months ago
"Once the suspect source is discovered and removed from the network" probably means that the infected computer is identified and isolate.
upvoted 1 times
...
...
ENGNET81
3 years, 11 months ago
"Once the suspected source of the virus is discovered and removed from the network" its means "Quarantine infected systems (isolate it) " so , the next step is "Schedule scans and run updates" (Answer is B)
upvoted 1 times
...
dnbly
4 years ago
B is correct but the wording of the question is so tricky that it's easy to get it wrong. I answered differently at first but after reading the question several times I can agree with B. I hope this question is reworded for the actual exam.
upvoted 1 times
...
shogo11
4 years ago
another trick question... they didn't use the word quarantine. why do they put these tricky worded questions to catch you out. it's annoying.
upvoted 2 times
...
harinezumi
4 years, 4 months ago
Yes, that was tricky, he already removed from the network but not the computer system itself.
upvoted 2 times
ep0ch
3 years, 6 months ago
The "source" of the virus was removed. I believe this means the computer was removed from the network, meaning B is correct.
upvoted 1 times
...
...
Takoyaki
4 years, 6 months ago
Scanning the device and removing the malware from it is the most correct answer. Had to think about this one for a bit. While the technician has isolated the device and supposed virus source, he has not explicitly run a scan of the device. Scanning will confirm if the suspected source was correct, and properly clean the device. Scheduling scans and performing Windows updates is incorrect; a scan should be conducted first before Windows updates and immediately, not on a timed schedule. Creating a restore point is incorrect; no scan has been explicitly performed. The malware may have persisted up to this point. End user education is incorrect; the technician has not yet completed implementing his solution.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago