200-201 Question 347
Select 3A financial organization is preparing its cybersecurity team to respond to potential ransomware attacks. As part of the preparation phase, the team is tasked with developing a comprehensive incident response plan. Which of the following actions should be included in the preparation phase to ensure an effective response to ransomware incidents?
- A
Establish and test data backup and recovery procedures.
- B
Conduct regular training and awareness programs for employees.
- C
Wait until a ransomware attack occurs to evaluate the response plan.
- D
Develop a communication plan to notify stakeholders during an incident.
- E
Perform a post-incident analysis to identify gaps in the response process.
Show answer and explanation
Correct answers: A, B, D
Explanation
The preparation phase focuses on proactive measures such as ensuring data recovery capability, training employees, and planning communication strategies. These steps help organizations respond effectively to ransomware incidents, reducing downtime and potential damage.
- A. Correct.
Establishing and testing data backup and recovery procedures is a critical preparation step to ensure business continuity in case of a ransomware attack. Without reliable backups, recovery may be impossible.
- B. Correct.
Training and awareness programs help employees recognize and avoid phishing or malware attempts, reducing the likelihood of a successful ransomware attack.
- C. Incorrect.
Waiting until an attack occurs to evaluate the response plan is a reactive approach and does not align with the preparation phase's proactive nature.
- D. Correct.
Developing a communication plan ensures that all stakeholders, including employees, customers, and partners, are informed during an incident, minimizing confusion and reputational damage.
- E. Incorrect.
Performing a post-incident analysis is part of the recovery and improvement phase, not the preparation phase.