Security and malware response: contain risk without destroying recoverability
For suspected malware, the safest sequence begins with scope and containment. Determine whether the device is still communicating, what account is involved, whether sensitive data or credentials are at risk, and whether the incident process requires preserving volatile evidence. Disconnecting a system can reduce harm, but powering it off may destroy memory evidence; the right choice depends on impact, evidence needs, and organizational procedure.
After containment, remove persistence and recover from a trusted state. That can involve malware removal, credential reset, patching, restoring known-good data, rebuilding, or replacing a compromised image. The key distinction is that symptom removal is not automatically eradication. If persistence, stolen credentials, or the exploited weakness remains, the problem can recur immediately.
Endpoint security also includes ordinary support decisions: least privilege, account lifecycle, encryption, screen locks, secure wireless configuration, browser hygiene, application permissions, removable media controls, backups, and secure disposal. On exam scenarios, ask which control addresses the stated risk rather than choosing the strongest-sounding control in the abstract.