350-701 · Question #511
A company has 5000 Windows users on its campus. Which two precautions should IT take to prevent WannaCry ransomware from spreading to all clients? (Choose two.)
The correct answer is B. Ensure that noncompliant endpoints are segmented off to contain any potential damage. D. Perform a posture check to allow only network access to (hose Windows devices that are already. To prevent WannaCry ransomware from spreading, IT should segment noncompliant endpoints to contain potential damage and perform a posture check to ensure only compliant Windows devices access the network.
Question
A company has 5000 Windows users on its campus. Which two precautions should IT take to prevent WannaCry ransomware from spreading to all clients? (Choose two.)
Options
- ASegment different departments to different IP blocks and enable Dynamic ARp inspection on all
- BEnsure that noncompliant endpoints are segmented off to contain any potential damage.
- CEnsure that a user cannot enter the network of another department.
- DPerform a posture check to allow only network access to (hose Windows devices that are already
- EPut all company users in the trusted segment of NGFW and put all servers to the DMZ segment
How the community answered
(39 responses)- A8% (3)
- B77% (30)
- C3% (1)
- E13% (5)
Why each option
To prevent WannaCry ransomware from spreading, IT should segment noncompliant endpoints to contain potential damage and perform a posture check to ensure only compliant Windows devices access the network.
While network segmentation and Dynamic ARP inspection are good security practices, they do not directly address the WannaCry vulnerability (SMB exploitation) as effectively as endpoint compliance and containment.
Network segmentation is crucial for containing the spread of malware like WannaCry, as isolating noncompliant or potentially infected endpoints severely limits the ransomware's ability to propagate laterally across the network.
This describes a form of network segmentation, but 'a user cannot enter the network of another department' is less precise than 'segment noncompliant endpoints' when specifically addressing ransomware containment and broad spread.
A posture check, often part of Network Access Control (NAC), verifies that endpoints meet specific security requirements (e.g., patched OS, updated antivirus) before granting network access, preventing unpatched devices susceptible to WannaCry from connecting.
Placing all users in a 'trusted segment' without further controls could facilitate rapid spread if an initial user device is compromised, as trust zones typically imply fewer restrictions, which is counterproductive for WannaCry prevention.
Concept tested: Ransomware prevention (WannaCry)
Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-221a
Topics
Community Discussion
No community discussion yet for this question.