300-215 Question 131
Select 3After conducting a post-incident analysis of a ransomware attack within your organization, you determine that the attackers exploited an outdated software vulnerability and used phishing emails to gain initial access. Which of the following actions should you recommend as part of your post-incident remediation plan?
- A
Implement a robust patch management program to ensure all systems are updated regularly.
- B
Conduct phishing awareness training for employees to reduce the likelihood of future successful attacks.
- C
Focus exclusively on deploying additional endpoint detection and response (EDR) tools across the organization.
- D
Perform a review of email filtering rules and improve spam and phishing detection capabilities.
- E
Rebuild all affected systems without addressing the root cause of the incident.
Show answer and explanation
Correct answers: A, B, D
Explanation
Post-incident recommendations should address both the technical and human factors that contributed to the incident. In this scenario, implementing a patch management program, improving phishing awareness, and enhancing email filtering are proactive measures that directly mitigate the risks identified in the attack. Exclusively focusing on one technology or failing to address root causes leaves the organization susceptible to future incidents.
- A. Correct.
Implementing a robust patch management program addresses the root cause of the attack by ensuring vulnerabilities are remediated proactively.
- B. Correct.
Phishing awareness training reduces the likelihood of employees falling victim to similar attacks in the future and strengthens the human element of cybersecurity.
- C. Incorrect.
While deploying EDR tools is valuable, focusing exclusively on them without addressing the root causes (phishing and patch management) is not a comprehensive solution.
- D. Correct.
Improving spam and phishing detection capabilities enhances the organization’s defenses against the initial access vector exploited by the attackers.
- E. Incorrect.
Rebuilding systems without addressing the root cause of the incident leaves the organization vulnerable to repeat attacks.