200-201 · Question #481
A group of company-owned endpoints were infected by ransomware via phishing email. Which two stakeholders must be involved in the containment phase? (Choose two.)
The correct answer is B. Chief Information Security Officer D. Incident Response Team Engineers. The CISO is responsible for overseeing the organization's overall security posture and responding to incidents. During the containment phase of an incident (such as a ransomware attack), the CISO is involved in high-level decision-making, coordinating with stakeholders, and ensur
Question
A group of company-owned endpoints were infected by ransomware via phishing email. Which two stakeholders must be involved in the containment phase? (Choose two.)
Options
- ATechnical Director
- BChief Information Security Officer
- COwners of the infected endpoints
- DIncident Response Team Engineers
- EChief Physical Security Officer
How the community answered
(16 responses)- A19% (3)
- B69% (11)
- C6% (1)
- E6% (1)
Explanation
The CISO is responsible for overseeing the organization's overall security posture and responding to incidents. During the containment phase of an incident (such as a ransomware attack), the CISO is involved in high-level decision-making, coordinating with stakeholders, and ensuring that proper containment strategies are implemented to minimize damage. The Incident Response (IR) Team Engineers are directly responsible for containing the ransomware infection. They take the technical actions needed to isolate affected systems, prevent the ransomware from spreading further, and restore services. Their expertise is critical for executing the containment plan effectively. While the Technical Director might be informed or involved in recovery planning, they are not typically part of the immediate containment process. The owners of infected endpoints may need to be informed, but they are not responsible for containment actions. The physical security officer deals with physical security aspects (e.g., securing buildings or physical access) and would not typically be involved in handling ransomware containment.
Topics
Community Discussion
No community discussion yet for this question.