ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 83 - CAS-004 discussion

Report
Export

An organization recently experienced a ransomware attack. The security team leader is concerned about the attack reoccurring. However, no further security measures have been implemented.

Which of the following processes can be used to identify potential prevention recommendations?

A.
Detection
Answers
A.
Detection
B.
Remediation
Answers
B.
Remediation
C.
Preparation
Answers
C.
Preparation
D.
Recovery
Answers
D.
Recovery
Suggested answer: C

Explanation:

Preparation is the process that can be used to identify potential prevention recommendations after a security incident, such as a ransomware attack. Preparation involves planning and implementing security measures to prevent or mitigate future incidents, such as by updating policies, procedures, or controls, conducting training or awareness campaigns, or acquiring new tools or resources. Detection is the process of discovering or identifying security incidents, not preventing them. Remediation is the process of containing or resolving security incidents, not preventing them. Recovery is the process of restoring normal operations after security incidents, not preventing them. Verified

Reference: https://www.comptia.org/blog/what-is-incident-response https://partners.comptia.org/docs/default-source/resources/casp-content-guide

asked 02/10/2024
Ahmed Khalifa
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first