When addressing a suspected malware infection in a corporate environment, what is the FIRST action to be taken to best ensure containment and prevent further spread of the infection?
Reformat the system drive
Create a restore point
Disconnect the system from network connections
Update the antivirus definitions and perform a system scan
Disconnecting the system from network connections is the critical initial step to prevent the malware from spreading to other systems or accessing network resources. This action effectively isolates the infected computer, helping to halt any potential communication with other systems or external control from attackers. Although updating antivirus definitions and performing a system scan are important subsequent steps, they do not immediately address the risk of the malware communicating with other systems. Reformatting the system drive or creating a restore point should only be considered once the system is secured and the extent of the infection assessed.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is it important to disconnect the system from network connections when dealing with malware?
Open an interactive chat with Bash
What should be done after disconnecting the infected system from the network?
Open an interactive chat with Bash
What are the potential risks of not disconnecting an infected system from the network?