Investigate and Verify Malware Symptoms for A+
Short answer
Start by confirming that the symptom is likely caused by malware. Typical quick checks: view running processes and startup entries, check system logs or Event Viewer for recent failures, confirm whether antivirus alerts occurred, ask the user about recent downloads or attachments, and note whether multiple devices show similar symptoms (possible network spread). Preserve volatile evidence minimally: document observed messages, save screenshots, and avoid actions that overwrite logs unless required to contain spread.
Why it appears on the exam
- Given a symptom list, select which items suggest malware vs hardware failure. - Choose the correct immediate action after observing a ransom message vs slow performance during an update. - Short prioritize verification steps to gather minimum evidence without delaying containment.
Key concepts
Concept 1
Required terms
verify symptoms: Confirming that observed behavior is consistent with malware rather than hardware failure, software misconfiguration, or user action. verify symptoms: Confirm that observed behavior (popups, redirects, disabled security, unknown processes) indicates possible malware.
Example
A user reports sudden repeated browser popups after clicking a link. Technician verifies by checking browser extensions, recent installs, and processes for unfamiliar executables before disconnecting.
Concept 2
How Investigate and Verify Malware Symptoms works
Start by confirming that the symptom is likely caused by malware. Typical quick checks: view running processes and startup entries, check system logs or Event Viewer for recent failures, confirm whether antivirus alerts occurred, ask the user about recent downloads or attachments, and note whether multiple devices show similar symptoms (possible network spread). Preserve volatile evidence minimally: document observed messages, save screenshots, and avoid actions that overwrite logs unless required to contain spread.
Example
System shows a ransom note on boot: technician documents the message (photo), avoids changing files, and proceeds to quarantine the machine.
Concept 3
Common confusion
- Mistaking failing hardware (e.g., failing HDD causing slow reads) for malware-induced slowness. Simple hardware checks (SMART, drives) can avoid unnecessary remediation. - Immediately reinstalling or reimaging without first verifying symptoms and preserving evidence when appropriate.
Example
Slow performance after Windows Update: technician checks CPU/Disk usage and Windows Update history to distinguish update activity from malware.
Concept 4
Core 2 (220-1202) question cues
Given a symptom list, select which items suggest malware vs hardware failure; Choose the correct immediate action after observing a ransom message vs slow performance during an update; Short prioritize verification steps to gather minimum evidence without delaying containment.
Example
A user reports sudden repeated browser popups after clicking a link. Technician verifies by checking browser extensions, recent installs, and processes for unfamiliar executables before disconnecting.
Sample questions
Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.
Q1.A technician is troubleshooting this situation: A user reports sudden repeated browser popups after clicking a link. Technician verifies by checking browser extensions, recent installs, and processes for unfamiliar executables before disconnecting. What should they identify?
Q2.A support ticket includes this clue: System shows a ransom note on boot: technician documents the message (photo), avoids changing files, and proceeds to quarantine the machine. Which concept is being tested?
Q3.A support scenario about Investigate and Verify Malware Symptoms feels similar to a nearby topic. What is the safest way to choose an answer?
Practice this lesson in Cultiv8
The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.
Continue in Cultiv8