100-160 Question 212
Select 3A company experiences a ransomware attack that encrypts its critical business data. Despite the attack, the company is able to resume operations within an hour by restoring data from backups stored in a secure offsite location. Which key cybersecurity practices contributed to minimizing downtime and data loss in this scenario?
- A
Regularly testing disaster recovery plans
- B
Implementing network segmentation
- C
Maintaining offline and offsite backups
- D
Using a firewall for perimeter security
- E
Developing a business continuity plan
Show answer and explanation
Correct answers: A, C, E
Explanation
This scenario highlights the importance of disaster recovery and business continuity planning in minimizing downtime and data loss during a cyberattack. Regular testing of disaster recovery plans ensures readiness, offline/offsite backups allow for quick restoration of data, and a well-designed business continuity plan ensures that operations can resume promptly, even in the face of a disruptive event.
- A. Correct.
Regularly testing disaster recovery plans ensures the organization can respond effectively during an incident and minimizes downtime, as demonstrated in this scenario.
- B. Incorrect.
Implementing network segmentation is a good cybersecurity practice but is not directly related to disaster recovery or business continuity in this context.
- C. Correct.
Maintaining offline and offsite backups is a critical component of disaster recovery, enabling the company to restore its data quickly after the ransomware attack.
- D. Incorrect.
Using a firewall is critical for perimeter security, but it does not directly contribute to recovering data or continuing business operations after an attack.
- E. Correct.
Developing a business continuity plan ensures that the organization has a structured approach to maintaining essential operations during and after a cyberattack.