300-215 · Question #53
An organization experienced a ransomware attack that resulted in the successful infection of their workstations within their network. As part of the incident response process, the organization's…
The correct answer is D. vulnerabilities present in the organization's software and systems that were exploited by the. A root cause analysis must trace back to the specific security gaps that allowed the ransomware to succeed - namely unpatched software, misconfigurations, or other exploitable vulnerabilities - so that mitigating those exact weaknesses will prevent future compromise.
Question
An organization experienced a ransomware attack that resulted in the successful infection of their workstations within their network. As part of the incident response process, the organization’s cybersecurity team must prepare a comprehensive root cause analysis report. This report aims to identify the primary factor or factors responsible for the successful ransomware attack and to formulate effective strategies to prevent similar incidents in the future. In this context, what should the cybersecurity engineer emphasize in the root cause analysis report to demonstrate the underlying cause of the incident?
Options
- Aevaluation of user awareness and training programs aimed at preventing ransomware attacks
- Banalysis of the organization's network architecture and security infrastructure
- Cdetailed examination of the ransomware variant, its encryption techniques, and command-and-
- Dvulnerabilities present in the organization's software and systems that were exploited by the
How the community answered
(18 responses)- A17% (3)
- B6% (1)
- C6% (1)
- D72% (13)
Explanation
A root cause analysis must trace back to the specific security gaps that allowed the ransomware to succeed - namely unpatched software, misconfigurations, or other exploitable vulnerabilities - so that mitigating those exact weaknesses will prevent future compromise.
Topics
Community Discussion
No community discussion yet for this question.