nerdexam
CompTIA

220-1102 · Question #657

An organization's critical database files were attacked with ransomware. The company refuses to pay the ransom tor a decryption key. All traces of the infection have been removed from the underlying…

The correct answer is D. Restore critical data from backup. When an organization refuses to pay the ransom for a decryption key after a ransomware attack, and all traces of the infection have been removed, the next critical step is: Restore critical data from backup: This is the most effective way to recover from a ransomware attack…

Security

Question

An organization's critical database files were attacked with ransomware. The company refuses to pay the ransom tor a decryption key. All traces of the infection have been removed from the underlying servers Which of me following should the company do next?

Options

  • AScan all of tie infected files with up-to-date, anti-malware cleaning software.
  • BFully patch the server operating systems hosting the fileshares.
  • CChange the files to be read-only.
  • DRestore critical data from backup.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    13% (4)
  • C
    9% (3)
  • D
    75% (24)

Explanation

When an organization refuses to pay the ransom for a decryption key after a ransomware attack, and all traces of the infection have been removed, the next critical step is: Restore critical data from backup: This is the most effective way to recover from a ransomware attack without paying the ransom. Assuming the organization has good backup practices, the backups should be free from infection and can be restored to get the systems operational again.

Topics

#Ransomware#Data recovery#Incident response#Backup and restore

Community Discussion

No community discussion yet for this question.

Full 220-1102 Practice