certslothcertsloth
220-1202/Topic 07

CompTIA / Foundational

Malware and Endpoint Recovery

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Contain, investigate, clean and prove trust again.

Must remember

Recognize suspicious behavior: unexpected browser redirects, disabled security tools, unknown persistence, unusual account activity, encrypted files or unexplained network traffic. Performance problems alone do not prove malware. Collect evidence and follow the incident procedure rather than running random cleanup tools.

Quarantine/isolate a suspected system as appropriate to protect others, preserving evidence when required. Update and use approved tools from a trusted environment. Safe Mode or offline scanning can help when the normal environment is unreliable. Remove persistence and entry points, not only the visible file.

Restore or rebuild from known-good sources when trust cannot be established. Verify backup integrity, patch the weakness, reset/revoke affected credentials and sessions, and re-enable protection. A restored infected backup or stolen live token can reintroduce compromise.

Browser security includes supported versions, trusted extensions, safe download handling and appropriate privacy settings. Clearing cache may fix stale content but does not revoke an attacker’s session or remove every malicious extension. Social-engineering recovery includes educating the user without blame and making reporting easy.

For ransomware or suspected data exposure, escalate to the authorized security/legal process. Do not promise that deleting malware means no data left the device. Document observed scope and uncertainty accurately.

Verify both technical health and the original user workflow. Monitor for recurrence, confirm backups and update the ticket/runbook with the established cause and prevention steps.

Choose under exam pressure

Requirement Choice and reason
Potential active compromise Follow authorized isolation/escalation and evidence procedures.
Cannot trust OS integrity Controlled rebuild from known-good media and verified data.
Credentials may be stolen Revoke/reset affected access through the appropriate identity process.

Traps

  • A malware scanner’s clean result is useful evidence, not absolute proof of trust.
  • Deleting a suspicious file does not necessarily remove persistence.

Active recall

1. Why isolate a compromised endpoint?

To limit spread or exfiltration while investigation/recovery proceeds.

2. Why verify backups before restore?

They may be infected, corrupted or incomplete.

3. Why revoke sessions after password changes?

Existing tokens can remain usable depending on the system.

4. Does removing ransomware prove no data was stolen?

No. Exfiltration requires separate investigation.

5. What should user education avoid?

Blame or shame that discourages prompt reporting.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.