QuestionQ210

Incident Management

An organization receives user complaints that some files have been encrypted, and the users are being asked to pay money to decrypt them. Which of the following is the BEST course of action?

  • A Isolate the affected systems.
  • B Conduct an impact assessment.
  • C Initiate incident response.
  • D Rebuild the affected systems.
Explanation

Ransom-driven file encryption is a ransomware incident and requires activation of the incident response process. Incident response provides the coordinated framework for containment, impact assessment, recovery, evidence preservation, and communication; isolating affected systems is one action performed within that process.

Community Discussion

No comments yet. Be the first to start the discussion!