200-201 Question 155
Select 4A medium-sized company has been hit by a ransomware attack. The attackers have encrypted critical business files and are demanding payment in cryptocurrency for the decryption key. As a cybersecurity analyst, what immediate actions should you take to mitigate further damage and begin recovery?
- A
Disconnect the affected systems from the network to prevent further spread of the ransomware.
- B
Pay the ransom immediately to recover access to the encrypted files.
- C
Report the incident to relevant authorities or cybersecurity organizations.
- D
Attempt to decrypt the files using publicly available decryption tools if applicable.
- E
Engage a professional incident response team to assist with containment and recovery.
Show answer and explanation
Correct answers: A, C, D, E
Explanation
When responding to a ransomware attack, the primary objective is to contain and mitigate the threat while initiating recovery efforts. Disconnecting systems prevents further spread, reporting ensures compliance and aids collective defense, and leveraging decryption tools or professional help maximizes recovery opportunities. Paying the ransom is discouraged due to its ethical and practical implications.
- A. Correct.
Disconnecting the affected systems from the network is critical to prevent the ransomware from spreading to other systems.
- B. Incorrect.
Paying the ransom is not recommended as it does not guarantee file recovery and may encourage further criminal activity.
- C. Correct.
Reporting the incident to authorities or cybersecurity organizations is important for legal compliance and to potentially help others by sharing threat intelligence.
- D. Correct.
Some ransomware variants may have known decryption tools available. Attempting to use them is a reasonable step if applicable.
- E. Correct.
Engaging a professional incident response team ensures expert assistance in containing the attack and recovering from the incident.