ExamGecko
Question list
Search
Search

Question 6 - CISM discussion

Report
Export

Which of the following presents the GREATEST challenge to the recovery of critical systems and data following a ransomware incident?

A.
Lack of encryption for backup data in transit
Answers
A.
Lack of encryption for backup data in transit
B.
Undefined or undocumented backup retention policies
Answers
B.
Undefined or undocumented backup retention policies
C.
Ineffective alert configurations for backup operations
Answers
C.
Ineffective alert configurations for backup operations
D.
Unavailable or corrupt data backups
Answers
D.
Unavailable or corrupt data backups
Suggested answer: D

Explanation:

A ransomware incident is a type of cyberattack that encrypts the victim's data and demands a ransom for its decryption. Ransomware can cause significant disruption and damage to critical systems and data, as well as financial losses and reputational harm. To recover from a ransomware incident, the organization needs to have reliable and accessible backups of its data, preferably in an encrypted format. However, if the backups are unavailable or corrupt, the organization will face a major challenge in restoring its data and operations.Therefore, option D is the most challenging factor for the recovery of critical systems and data following a ransomware incident.Reference= CISA MS-ISAC Ransomware Guide1, page 9; How to Write an Incident Response Plan for Ransomware Recovery2.

asked 01/10/2024
Mark Green
45 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first