nerdexam
CompTIA

CAS-005 · Question #310

While investigating a security event an analyst finds evidence that a user opened an email attachment from an unknown source. Shortly after the user opened the attachment, a group of servers…

The correct answer is B. Isolate the servers to prevent the spread. An analyst discovered a ransomware attack encrypting servers after a user opened an email attachment, with a payment demand and no company response plan.

Submitted by salim_om· Mar 6, 2026Security Operations

Question

While investigating a security event an analyst finds evidence that a user opened an email attachment from an unknown source. Shortly after the user opened the attachment, a group of servers experienced a large amount of network and resource activity. Upon investigating the servers, the analyst discovers the servers were encrypted by ransomware that is demanding payment within 48 hours or all data will be destroyed. The company has no response plans for ransomware. Which of the following is the next step the analyst should take after reporting the incident to the management team?

Options

  • APay the ransom within 48 hours
  • BIsolate the servers to prevent the spread
  • CNotify law enforcement
  • DRequest that the affected servers be restored immediately

How the community answered

(40 responses)
  • A
    8% (3)
  • B
    75% (30)
  • C
    15% (6)
  • D
    3% (1)

Why each option

An analyst discovered a ransomware attack encrypting servers after a user opened an email attachment, with a payment demand and no company response plan.

APay the ransom within 48 hours

Paying the ransom is a business decision and typically a last resort, not the immediate technical step an analyst should take, especially without a response plan or management directive.

BIsolate the servers to prevent the spreadCorrect

After reporting a ransomware incident to management, the most critical immediate technical step is to isolate the affected servers and any potentially compromised systems from the network. This prevents the ransomware from spreading further, encrypting more data, or exfiltrating information, thereby containing the incident.

CNotify law enforcement

Notifying law enforcement is an important step in incident response but usually follows initial containment and assessment; it is not the immediate technical action to prevent further damage.

DRequest that the affected servers be restored immediately

Requesting server restoration is part of the recovery phase. Attempting restoration before containment is complete risks re-infection or further spread if the source of the infection is not isolated.

Concept tested: Incident response - containment phase

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/incident-response-overview#containment

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice