A security administrator has isolated a computer system because it was targeted by a ransomware attack. Which of the following should the security administrator do to recover from this attack in the most secure way?
A Check if file versioning is enabled and restore the files. B Restore the system from a baseline snapshot. C Determine if the encryption key can be recovered. If it can, restore the files. D Seek approval from senior leadership to pay the ransom and unencrypt the files with the provided key. Show Answer Answer Explanation Restoring the isolated system from a known-good baseline snapshot avoids the uncertainty of relying on the attacker's cooperation or on artifacts that may themselves be compromised, making it the most secure recovery path. File versioning may have been created or tampered with during the attack window and cannot be trusted as a clean source, attempting to recover the encryption key is unreliable and does not guarantee removal of any implanted malware, and paying the ransom funds criminal activity while providing no assurance that a working decryption key will be delivered, so security guidance from bodies such as CISA and NIST explicitly discourages it in favor of restoring from verified clean backups or baselines.
Community Discussion