2.3 - Anti-Malware Tools Flashcards
1
Q
Windows Recovery Environment
A
- Very powerful
-
Very dangerous
– Last resort - Complete control
– Fix your problems before the system starts
– Remove malicious software - Requires additional information
– Use, copy, rename, or replace operating system files
and folders
– Enable or disable service or device startup
– Repair the file system boot sector or the
master boot record (MBR)
2
Q
Starting the console
A
- All Windows versions
– Hold Shift key while clicking Restart
– Or boot from installation media - Windows 10
– Settings > Update and Security > Recovery >
Advanced startup - Windows 11
– System > Recovery > Advanced startup > Restart now - After rebooting
– Troubleshoot > Advanced Options > Command Prompt
3
Q
Anti-virus and anti-malware
A
- You need both
– Often included together - Real-time options
– Not just an on-demand scan - Modern anti-malware recognizes malicious activity
– Doesn’t require a specific set of signatures
4
Q
Software firewalls
A
- Monitor the local computer
– Alert on unknown or unauthorized
network communication - Prevent malware communication
– Downloads after infection
– Botnet communication - Use Microsoft Defender Firewall - At a minimum
- Runs by default
– Constantly monitoring
– Any network connection
5
Q
Anti-phishing training
A
- No single technology can stop social engineering
– Don’t give away private information
– The user is the best anti-phishing - Extensive training - Avoid becoming a victim
- Test the users
– Send a phishing email
– Find out who clicks and gives up information - Train again
6
Q
End user education
A
- One on one - Personal training
- Posters and signs - High visibility
- Message board posting - The real kind
- Login message - These become invisible
- Intranet page - Always available
7
Q
OS reinstallation
A
- Only one way to guarantee malware removal
– Delete everything
– Install from scratch - Restore from backup (fast)
– As long as the backup is not also infected - Manual installation (slowest)
– Backup data files
– Install Windows from installation media - Image the system (fastest)
– User’s data files are on a network share
– Recover from a prebuilt image