200-201 Question 154
Select 3A financial institution has experienced a ransomware attack where critical customer data was encrypted. The attackers are demanding a payment in cryptocurrency to release the decryption key. As a cybersecurity analyst, which of the following actions should you prioritize to respond to this incident effectively?
- A
Isolate the affected systems from the network to prevent further spread.
- B
Pay the ransom immediately to recover access to the data as quickly as possible.
- C
Identify and preserve forensic evidence for a potential investigation.
- D
Restore the affected systems from the most recent clean backup.
- E
Communicate the incident to the attackers to negotiate for a reduced ransom.
Show answer and explanation
Correct answers: A, C, D
Explanation
The correct approach to handling a ransomware attack involves isolating affected systems to prevent the malware from spreading, preserving forensic evidence for investigation, and restoring data from clean backups to recover operations. Paying the ransom and engaging with attackers are discouraged due to ethical, security, and operational risks.
- A. Correct.
Isolating the affected systems is critical to containing the spread of the ransomware to other devices or networks.
- B. Incorrect.
Paying the ransom is not recommended as it does not guarantee the recovery of data and encourages further criminal activity.
- C. Correct.
Preserving forensic evidence is vital for understanding the attack vector and may assist in legal or investigative processes.
- D. Correct.
Restoring from a clean backup is an essential step to recover systems and data without depending on the attackers.
- E. Incorrect.
Communicating with attackers is risky and not recommended, as it may escalate the situation or expose the organization to further threats.