100-160 Question 168
Select 3You are performing a routine vulnerability scan on your organization's systems and notice a critical severity alert in the scan logs, indicating malware was detected on a workstation. What steps should you take to address this issue effectively?
- A
Isolate the affected workstation from the network immediately.
- B
Ignore the alert if the user of the workstation reports no issues.
- C
Review the scan logs to gather more details about the malware and its behavior.
- D
Run a full antivirus/antimalware scan on the affected workstation to remove any threats.
- E
Reformat the workstation without investigating the malware further.
Show answer and explanation
Correct answers: A, C, D
Explanation
When malware is detected, the priority is to isolate the affected system to contain the threat, analyze the scan logs for details, and use security tools to remediate the issue. Ignoring alerts or taking drastic actions like reformatting without proper investigation can lead to incomplete resolution or unnecessary disruption. Following a structured response ensures effective mitigation and minimizes impact.
- A. Correct.
Correct. Isolating the affected workstation prevents the malware from spreading to other devices on the network.
- B. Incorrect.
Incorrect. Ignoring the alert based on user feedback is not a valid action. Malware can operate silently without causing immediate visible issues.
- C. Correct.
Correct. Reviewing the scan logs helps you understand the nature of the malware, its potential impact, and the next steps for remediation.
- D. Correct.
Correct. Running a full antivirus/antimalware scan is a critical step to identify and remove the malicious software from the affected system.
- E. Incorrect.
Incorrect. Reformatting the workstation without investigating the malware further could result in the loss of forensic data needed for analysis and may lead to unnecessary downtime.