300-215 Question 207
Select 3During an ongoing ransomware attack on your organization's network, you are tasked with initiating an incident response plan. Which of the following are primary goals of incident response in this scenario?
- A
Minimize the impact of the incident on business operations
- B
Identify and document the root cause of the incident
- C
Ensure that all affected systems are immediately disconnected from the network
- D
Restore normal operations as quickly as possible
- E
Punish the attackers by launching counter-attacks
Show answer and explanation
Correct answers: A, B, D
Explanation
The primary goals of incident response include minimizing the impact on business operations, identifying the root cause to prevent recurrence, and restoring normal operations promptly. These goals ensure the organization can recover effectively while maintaining forensic integrity and business continuity. Ethical and professional handling of incidents is critical, and retaliatory actions like counter-attacks are not part of incident response objectives.
- A. Correct.
Minimizing the impact of the incident on business operations is a primary goal of incident response, as it ensures the organization can continue functioning while the issue is being addressed.
- B. Correct.
Identifying and documenting the root cause of the incident is necessary to prevent similar incidents in the future and is a fundamental part of the incident response process.
- C. Incorrect.
While disconnecting affected systems may sometimes be necessary, it is not always the primary goal. The response must be measured and aligned with the overall plan to avoid further disruption.
- D. Correct.
Restoring normal operations as quickly as possible is a key objective of incident response, ensuring minimal downtime and business continuity.
- E. Incorrect.
Launching counter-attacks is not a legitimate or ethical goal of incident response and is not recommended in any professional cybersecurity practice.