nerdexam
Cisco

200-201 · Question #481

A group of company-owned endpoints were infected by ransomware via phishing email. Which two stakeholders must be involved in the containment phase? (Choose two.)

The correct answer is B. Chief Information Security Officer D. Incident Response Team Engineers. The CISO is responsible for overseeing the organization's overall security posture and responding to incidents. During the containment phase of an incident (such as a ransomware attack), the CISO is involved in high-level decision-making, coordinating with stakeholders, and ensur

Submitted by kim_seoul· Mar 6, 2026Security Policies and Procedures

Question

A group of company-owned endpoints were infected by ransomware via phishing email. Which two stakeholders must be involved in the containment phase? (Choose two.)

Options

  • ATechnical Director
  • BChief Information Security Officer
  • COwners of the infected endpoints
  • DIncident Response Team Engineers
  • EChief Physical Security Officer

How the community answered

(16 responses)
  • A
    19% (3)
  • B
    69% (11)
  • C
    6% (1)
  • E
    6% (1)

Explanation

The CISO is responsible for overseeing the organization's overall security posture and responding to incidents. During the containment phase of an incident (such as a ransomware attack), the CISO is involved in high-level decision-making, coordinating with stakeholders, and ensuring that proper containment strategies are implemented to minimize damage. The Incident Response (IR) Team Engineers are directly responsible for containing the ransomware infection. They take the technical actions needed to isolate affected systems, prevent the ransomware from spreading further, and restore services. Their expertise is critical for executing the containment plan effectively. While the Technical Director might be informed or involved in recovery planning, they are not typically part of the immediate containment process. The owners of infected endpoints may need to be informed, but they are not responsible for containment actions. The physical security officer deals with physical security aspects (e.g., securing buildings or physical access) and would not typically be involved in handling ransomware containment.

Topics

#incident response#ransomware#incident management#stakeholder communication

Community Discussion

No community discussion yet for this question.

Full 200-201 Practice