100-160 Question 217
Select 3An organization has recently experienced a ransomware attack that encrypted critical business files. The IT team is tasked with recovering operations as quickly as possible while ensuring such incidents can be better mitigated in the future. Which of the following actions should be included in their disaster recovery plan (DRP) to address this situation?
- A
Implement regular backups and test the restoration process.
- B
Deploy an Intrusion Prevention System (IPS) to block malicious traffic.
- C
Develop a communication plan to notify stakeholders during incidents.
- D
Establish a procedure to identify and isolate affected systems.
- E
Purchase additional antivirus licenses for all endpoints.
Show answer and explanation
Correct answers: A, C, D
Explanation
A strong disaster recovery plan (DRP) focuses on restoring operations and minimizing downtime after an incident like a ransomware attack. Regular backups, a stakeholder communication plan, and procedures to isolate and contain the issue ensure effective recovery and continuity. Preventive measures, such as deploying an IPS or purchasing antivirus licenses, are important for cybersecurity but are not the primary focus of a DRP.
- A. Correct.
Regular backups and testing the restoration process are essential to recovering encrypted files and ensuring continuity during ransomware attacks, making this a key element of a DRP.
- B. Incorrect.
While deploying an IPS is a preventive security control, it is more relevant to general network security than specifically addressing disaster recovery for ransomware incidents.
- C. Correct.
A communication plan to notify stakeholders is crucial in a DRP to manage expectations, coordinate responses, and avoid reputational damage during incidents.
- D. Correct.
Establishing a procedure to identify and isolate affected systems is a critical corrective control to contain the ransomware and limit its spread, which is vital for disaster recovery.
- E. Incorrect.
Purchasing additional antivirus licenses is a preventive action but does not directly address recovery efforts or improve business continuity after an incident.