nerdexam
Cisco

300-215 · Question #122

Which step should occur IMMEDIATELY after identifying ransomware actively encrypting files on multiple hosts?

The correct answer is D. Isolate impacted systems. Active ransomware must be contained first to stop propagation and data loss. Full forensic acquisition comes after isolation.

Submitted by hans_de· Mar 6, 2026Incident Response Techniques

Question

Which step should occur IMMEDIATELY after identifying ransomware actively encrypting files on multiple hosts?

Options

  • ARestore from backup
  • BDisable affected user accounts
  • CCapture forensic disk images
  • DIsolate impacted systems

How the community answered

(32 responses)
  • A
    6% (2)
  • B
    9% (3)
  • C
    3% (1)
  • D
    81% (26)

Explanation

Active ransomware must be contained first to stop propagation and data loss. Full forensic acquisition comes after isolation.

Topics

#Incident response#Ransomware#Containment#System isolation

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice