350-201 Question 31
Select 3Your organization experiences a ransomware attack that encrypts critical files, and the attackers demand payment for decryption. As the cybersecurity lead, you initiate the incident response workflow. Which steps should you prioritize to effectively handle this incident based on Cisco's recommended incident response process?
- A
Contain the ransomware infection to prevent further spread across the network.
- B
Immediately pay the ransom to ensure quick recovery of encrypted files.
- C
Identify the scope and impact of the ransomware attack through logs and forensic analysis.
- D
Notify relevant stakeholders, including legal teams and executive leadership, about the attack.
- E
Begin eradicating the ransomware by cleaning infected systems and restoring from backups.
Show answer and explanation
Correct answers: A, C, D
Explanation
The Cisco incident response workflow emphasizes a structured approach to handling cybersecurity incidents. In this scenario, prioritizing containment, identifying the scope of the attack, and notifying stakeholders align with best practices. Containment limits the attack's spread, identification provides crucial insights for informed decision-making, and notifying key stakeholders ensures a coordinated response. While eradication is important, it typically occurs after these initial steps to ensure the response is effective and comprehensive. Paying the ransom is not a recommended action under Cisco's guidelines, as it introduces additional risks and uncertainty.
- A. Correct.
Containing the infection is a critical step in incident response to prevent further damage and spread of the ransomware. This step helps isolate the compromised systems and limits the attack's impact.
- B. Incorrect.
Paying the ransom is not recommended as it does not guarantee recovery of encrypted files and could encourage further attacks. This is not a best practice in incident response.
- C. Correct.
Identifying the scope and impact of the attack is essential for understanding the severity and extent of the compromise. This informs subsequent actions in the response workflow.
- D. Correct.
Notifying relevant stakeholders ensures that appropriate teams are informed and can assist with containment, legal compliance, and communication strategies.
- E. Incorrect.
Eradicating the ransomware is important, but it generally comes after containment and identification. Jumping to eradication without proper analysis could lead to incomplete remediation or further issues.