CERTIFIED-IN-CYBERSECURITY · Question #555
A junior cybersecurity analyst has detected a ransomware attack on the company's servers and has activated the incident response team. Which is the next BEST course of action? ()
The correct answer is D. Attempt to isolate any compromised servers to prevent further damage. When a ransomware attack is confirmed and the incident response team is activated, the immediate priority is containment - isolating compromised servers to prevent the ransomware from spreading laterally across the network. This follows the standard incident response lifecycle…
Question
A junior cybersecurity analyst has detected a ransomware attack on the company's servers and has activated the incident response team. Which is the next BEST course of action? ()
Options
- AUpdate all server anti-virus software with the latest updates
- BGenerate support tickets to restore the affected systems to their previous state
- CInvestigate how the ransomware entered the company's servers
- DAttempt to isolate any compromised servers to prevent further damage
How the community answered
(30 responses)- A7% (2)
- B3% (1)
- C13% (4)
- D77% (23)
Explanation
When a ransomware attack is confirmed and the incident response team is activated, the immediate priority is containment - isolating compromised servers to prevent the ransomware from spreading laterally across the network. This follows the standard incident response lifecycle: Preparation → Identification → Containment → Eradication → Recovery → Lessons Learned. Updating antivirus (A) and restoring systems (B) come later in the eradication and recovery phases. Investigating the attack vector (C) is important but happens after containment so the investigation doesn't inadvertently spread the threat further.
Topics
Community Discussion
No community discussion yet for this question.