nerdexam
CompTIA

CAS-005 · Question #430

A security administrator has isolated a computer system because it was targeted by a ransomware attack. Which of the following should the security administrator do to recover from this attack in the m

The correct answer is B. Restore the system from a baseline snapshot.. Restoring from a known-good, immutable snapshot ensures you return the system to a clean, pre-infection state without any residual ransomware artifacts or potential backdoors. Snapshots are typically protected from tampering and provide a trusted recovery point, making this the m

Submitted by renata2k· Mar 6, 2026Security Operations

Question

A security administrator has isolated a computer system because it was targeted by a ransomware attack. Which of the following should the security administrator do to recover from this attack in the most secure way?

Options

  • ACheck if file versioning is enabled and restore the files.
  • BRestore the system from a baseline snapshot.
  • CDetermine if the encryption key can be recovered. If it can, restore the files.
  • DSeek approval from senior leadership to pay the ransom and unencrypt the files with the provided

How the community answered

(49 responses)
  • A
    4% (2)
  • B
    84% (41)
  • C
    2% (1)
  • D
    10% (5)

Explanation

Restoring from a known-good, immutable snapshot ensures you return the system to a clean, pre-infection state without any residual ransomware artifacts or potential backdoors. Snapshots are typically protected from tampering and provide a trusted recovery point, making this the most secure and reliable remediation method.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice