ExamGecko
Question list
Search
Search

Question 505 - CISM discussion

Report
Export

Which of the following eradication methods is MOST appropriate when responding to an incident resulting in malware on an application server?

A.
Disconnect the system from the network.
Answers
A.
Disconnect the system from the network.
B.
Change passwords on the compromised system.
Answers
B.
Change passwords on the compromised system.
C.
Restore the system from a known good backup.
Answers
C.
Restore the system from a known good backup.
D.
Perform operation system hardening.
Answers
D.
Perform operation system hardening.
Suggested answer: C

Explanation:

Restoring the system from a known good backup is the most appropriate eradication method when responding to an incident resulting in malware on an application server, as it ensures that the system is free of any malicious code and that the data and applications are consistent with the expected state. Disconnecting the system from the network may prevent further spread of the malware, but it does not eradicate it from the system. Changing passwords on the compromised system may reduce the risk of unauthorized access, but it does not remove the malware from the system. Performing operation system hardening may improve the security configuration of the system, but it does not guarantee that the malware is eliminated from the system.

Reference= CISM Review Manual 2022, page 3131; CISM Exam Content Outline, Domain 4, Task 4.4

asked 01/10/2024
Ntombifuthi Shabangu
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first