300-215 Question 132
Select 4After a recent ransomware incident targeting your organization, you are tasked with recommending actions based on the post-incident analysis. The analysis reveals that the attack exploited unpatched software vulnerabilities, and the incident response team observed delays in detecting the breach due to insufficient logging. Which actions should you recommend to prevent similar incidents in the future?
- A
Implement a robust patch management process to ensure timely updates.
- B
Enhance logging and monitoring capabilities to improve breach detection.
- C
Disable all external network access to prevent future attacks.
- D
Conduct regular employee training on recognizing phishing attempts.
- E
Perform periodic tabletop exercises to simulate ransomware incidents.
Show answer and explanation
Correct answers: A, B, D, E
Explanation
Based on the post-incident analysis, the identified weaknesses in patch management and logging were exploited in the ransomware attack. Addressing these issues with patch management and logging enhancements are key recommendations. Additionally, proactive measures such as employee training and tabletop exercises improve overall security posture and readiness, while disabling external network access is not a feasible solution.
- A. Correct.
Implementing a robust patch management process addresses the root cause of the incident by ensuring vulnerabilities are patched in a timely manner, reducing the attack surface.
- B. Correct.
Enhancing logging and monitoring capabilities directly mitigates the issue of delayed breach detection observed during the incident.
- C. Incorrect.
Disabling all external network access is not a practical recommendation as it would severely disrupt business operations. Instead, proper security controls should be implemented to secure external access.
- D. Correct.
Conducting regular employee training on recognizing phishing attempts helps reduce the likelihood of users falling victim to social engineering tactics often used to deliver ransomware.
- E. Correct.
Periodic tabletop exercises increase organizational preparedness and improve the effectiveness of incident response plans for ransomware or similar incidents.