3.2 and 3.3 Troubleshooting Workstation Security Flashcards
List the seven steps, in order, of the malware removal process
- Identify and research malware symptoms
- Quarantine the infected systems
- Disable System Restore (if Windows OS)
- Remediate the infected system
- Schedule scans and run updates
- Enable System Restore and create a restore point (Windows
- Educate the end-user
Which two steps of the malware removal process are specific to Windows machines?
Step 3 (Disable System Restore) and Step 6 (Enable System Restore and create a restore point)
What is step 4 of the malware removal process?
Remediate the infected system
Quarantining the infected system should be done after what?
Identifying and researching malware symptoms
What is a PUA?
Potentially Unwanted Application
What might you use Nmap to find?
- Which devices are running on the network
- Open ports and services
- Vulnerabilites
What does netcat allow users to do?
Read from and write to network connections using TCP or UDP
How would you quarantine an infected system?
By moving it into a logically or physically isolated secure segment of the network
What are some different methods that could be used to logically isolate an infected system?
VLANs, access controls, encryption, partitioning
What sort of environment should be created to scan and test an infected computer?
A sandbox environment
Disabling System Restore does what?
Turns off automated backup systems, such as cloud and external disk backups
What is the ultimate effect of disabling System Restore?
The computer is prevented from returning to a previous state if the OS happens to become unstable
Why might System Restore be disabled?
Because it prevents a computer from returning to a previous state, it also prevents the re-infection of said computer with malware that may have been present at the created restoration point
Give the two main parts of remediating infected systems
- Updating anti-malware software
- Implementing scanning and removal techniques
List the four steps involved in scanning and removal
- Reboot in safe mode, run scanning/removal tools
- Turn off necessary services/background tasks by running task manager, regedit, msconfig
- Boot PC using Windows recovery/installation disk
- Re-image/re-install system from good backup/installation disk