nerdexam
Isaca

CGEIT · Question #46

The CIO of an enterprise learns the payroll server of a competitor has been the victim of ransomware. To help plan for the possibility of ransomed corporate data, what should be the ClO's FIRST…

The correct answer is C. Request a targeted risk assessment. Following a competitor's ransomware attack on a payroll server, the CIO's first course of action to plan for potential corporate data ransomware should be to request a targeted risk assessment.

Submitted by kev92· Apr 18, 2026Risk Optimization

Question

The CIO of an enterprise learns the payroll server of a competitor has been the victim of ransomware. To help plan for the possibility of ransomed corporate data, what should be the ClO's FIRST course of action?

Options

  • ARequire development of key risk indicators (KRls).
  • BDevelop a policy to address ransomware.
  • CRequest a targeted risk assessment.
  • DBack up corporate data to a secure location.

How the community answered

(23 responses)
  • A
    9% (2)
  • B
    4% (1)
  • C
    70% (16)
  • D
    17% (4)

Why each option

Following a competitor's ransomware attack on a payroll server, the CIO's first course of action to plan for potential corporate data ransomware should be to request a targeted risk assessment.

ARequire development of key risk indicators (KRls).

Requiring development of Key Risk Indicators (KRIs) is a step for ongoing monitoring, not the immediate first response to a specific, emerging threat identified by an incident.

BDevelop a policy to address ransomware.

Developing a policy to address ransomware is an important mitigation strategy, but it should be informed by the findings and specific risks identified in a targeted risk assessment.

CRequest a targeted risk assessment.Correct

A targeted risk assessment is the most effective first step because it specifically investigates the enterprise's unique vulnerabilities, exposure, and potential impact related to ransomware on critical corporate data, similar to the competitor's incident. This assessment provides a clear understanding of the threat landscape and informs the most appropriate and effective mitigation strategies before implementation.

DBack up corporate data to a secure location.

Backing up corporate data is a critical preventative control, but as the 'first course of action' for a CIO, a risk assessment determines if the *current* backup strategy is sufficient or needs immediate enhancement for this specific threat.

Concept tested: Incident-driven risk assessment

Topics

#Ransomware#Risk Assessment#Risk Management Process#CIO Responsibilities

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice