ExamGecko
Question list
Search
Search

Related questions

Question 72 - CISA discussion

Report
Export

A data breach has occurred due lo malware. Which of the following should be the FIRST course of action?

A.
Notify the cyber insurance company.
Answers
A.
Notify the cyber insurance company.
B.
Shut down the affected systems.
Answers
B.
Shut down the affected systems.
C.
Quarantine the impacted systems.
Answers
C.
Quarantine the impacted systems.
D.
Notify customers of the breach.
Answers
D.
Notify customers of the breach.
Suggested answer: C

Explanation:

The first course of action when a data breach has occurred due to malware is to quarantine the impacted systems. This means isolating the infected systems from the rest of the network and preventing any further communication or data transfer with them. This can help contain the spread of the malware, limit the damage and exposure of sensitive data, and facilitate the investigation and remediation of the incident. Quarantining the impacted systems can also help preserve the evidence and logs that may be needed for forensic analysis or legal action.

[1] provides a guide on how to respond to a data breach caused by malware and recommends quarantining the impacted systems as the first step.

[2] explains what is malware and how it can cause data breaches, and suggests quarantining the infected devices as a best practice.

[3] describes the steps involved in quarantining a system infected by malware and the benefits of doing so.

asked 18/09/2024
Dirk van der Watt
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first