Question: If your WordPress site is seriously compromised, what is the best course of action to return your site to good health?

  1. Determine the date of the attack and restore your site to a backup point prior to that date.
  2. Hire a third-party service to clean up your site because it is difficult for someone who is not a WordPress security expert to find and remove all traces of an attack.
  3. Manually delete suspicious files on the server and delete any database tables that are not core WordPress.
  4. Change your hosting password, your WordPress admin password, and your database password.

Answer: The correct answer of the above question is Option B:Hire a third-party service to clean up your site because it is difficult for someone who is not a WordPress security expert to find and remove all traces of an attack.