QuestionQ3

Security Operations

A security administrator has isolated a computer system because it was targeted by a ransomware attack. Which of the following should the security administrator do to recover from this attack in the most secure way?

Explanation

Restoring the isolated system from a known-good baseline snapshot avoids the uncertainty of relying on the attacker's cooperation or on artifacts that may themselves be compromised, making it the most secure recovery path. File versioning may have been created or tampered with during the attack window and cannot be trusted as a clean source, attempting to recover the encryption key is unreliable and does not guarantee removal of any implanted malware, and paying the ransom funds criminal activity while providing no assurance that a working decryption key will be delivered, so security guidance from bodies such as CISA and NIST explicitly discourages it in favor of restoring from verified clean backups or baselines.

Community Discussion

No comments yet. Be the first to start the discussion!