ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 91 - CAS-004 discussion

Report
Export

Ransomware encrypted the entire human resources fileshare for a large financial institution. Security operations personnel were unaware of the activity until it was too late to stop it. The restoration will take approximately four hours, and the last backup occurred 48 hours ago. The management team has indicated that the RPO for a disaster recovery event for this data classification is 24 hours.

Based on RPO requirements, which of the following recommendations should the management team make?

A.
Leave the current backup schedule intact and pay the ransom to decrypt the data.
Answers
A.
Leave the current backup schedule intact and pay the ransom to decrypt the data.
B.
Leave the current backup schedule intact and make the human resources fileshare read-only.
Answers
B.
Leave the current backup schedule intact and make the human resources fileshare read-only.
C.
Increase the frequency of backups and create SIEM alerts for IOCs.
Answers
C.
Increase the frequency of backups and create SIEM alerts for IOCs.
D.
Decrease the frequency of backups and pay the ransom to decrypt the data.
Answers
D.
Decrease the frequency of backups and pay the ransom to decrypt the data.
Suggested answer: C

Explanation:

Increasing the frequency of backups and creating SIEM (security information and event management) alerts for IOCs (indicators of compromise) are the best recommendations that the management team can make based on RPO (recovery point objective) requirements. RPO is a metric that defines the maximum acceptable amount of data loss that can occur during a disaster recovery event. Increasing the frequency of backups can reduce the amount of data loss that can occur, as it can create more recent copies or snapshots of the data. Creating SIEM alerts for IOCs can help detect and respond to ransomware attacks, as it can collect, correlate, and analyze security events and data from various sources and generate alerts based on predefined rules or thresholds. Leaving the current backup schedule intact and paying the ransom to decrypt the data are not good recommendations, as they could result in more data loss than the RPO allows, as well as encourage more ransomware attacks or expose the company to legal or ethical issues. Leaving the current backup schedule intact and making the human resources fileshare read-only are not good recommendations, as they could result in more data loss than the RPO allows, as well as affect the normal operations or functionality of the fileshare. Decreasing the frequency of backups and paying the ransom to decrypt the data are not good recommendations, as they could result in more data loss than the RPO allows, as well as increase the risk of losing data due to less frequent backups or unreliable decryption. Verified

Reference: https://www.comptia.org/blog/what-is-rpo https://partners.comptia.org/docs/default-source/resources/casp-content-guide

asked 02/10/2024
Aurelio Chavez
48 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first