nerdexam
Isaca

CISM · Question #243

Which of the following should an information security manager do FIRST upon learning that a competitor has experienced a ransomware attack?

The correct answer is D. Review the current risk assessment.. Upon learning that a competitor has experienced a ransomware attack, the first step for an information security manager should be to review the current risk assessment. This ensures that the organization’s exposure to similar risks is understood and that the necessary controls an

Submitted by tyler.j· Apr 18, 2026Information Security Risk Management

Question

Which of the following should an information security manager do FIRST upon learning that a competitor has experienced a ransomware attack?

Options

  • APerform a full data backup.
  • BConduct ransomware awareness training for all staff.
  • CUpdate indicators of compromise in the security systems.
  • DReview the current risk assessment.

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    5% (2)
  • C
    11% (5)
  • D
    82% (36)

Explanation

Upon learning that a competitor has experienced a ransomware attack, the first step for an information security manager should be to review the current risk assessment. This ensures that the organization’s exposure to similar risks is understood and that the necessary controls and preventive measures are in place to mitigate such threats. This action will guide further responses, such as backups or system updates, based on the specific risks identified.

Topics

#Risk Assessment#Threat Intelligence#Ransomware

Community Discussion

No community discussion yet for this question.

Full CISM Practice