100-160 Question 211
Single answerA company has experienced a ransomware attack that has encrypted critical customer data. The IT team is unable to recover the data from backups due to improper backup testing. What is the primary reason why disaster recovery and business continuity planning would have been helpful in this scenario?
- A
To ensure that backups are regularly tested and functional before an incident occurs
- B
To prevent all types of cybersecurity incidents from impacting the organization
- C
To reduce the likelihood of ransomware attacks by implementing antivirus software
- D
To provide a clear process to restore operations and minimize downtime after an incident
Show answer and explanation
Correct answer: A
Explanation
Disaster recovery and business continuity planning are critical for ensuring that an organization can respond to and recover from incidents like ransomware attacks. Regular testing of backups is a key component of these plans, as it ensures data can be restored when needed. In this scenario, such planning would have identified the issue with the backups before the attack occurred, allowing for a functional recovery process.
- A. Correct.
This is correct because disaster recovery and business continuity planning emphasize the importance of testing backups to ensure that they work effectively during a real incident.
- B. Incorrect.
This is incorrect because disaster recovery and business continuity planning cannot prevent all cybersecurity incidents; they are focused on response and recovery.
- C. Incorrect.
This is incorrect because installing antivirus software is a preventive measure, not a core part of disaster recovery or business continuity planning.
- D. Incorrect.
This is partially correct but not the primary focus in this scenario. While disaster recovery does involve minimizing downtime, the specific issue here is related to testing backups.