CISM · Question #49
A new type of ransomware has infected an organization's network. Which of the following would have BEST enabled the organization to detect this situation?
The correct answer is D. Monitoring of anomalies in system behavior. Detecting a new type of ransomware is best achieved through monitoring anomalies in system behavior, as traditional signature-based detection may be ineffective against unknown threats.
Question
A new type of ransomware has infected an organization's network. Which of the following would have BEST enabled the organization to detect this situation?
Options
- APeriodic information security training for end users
- BUse of integrated patch deployment tools
- CRegular review of the threat landscape
- DMonitoring of anomalies in system behavior
How the community answered
(60 responses)- A12% (7)
- B3% (2)
- C7% (4)
- D78% (47)
Why each option
Detecting a new type of ransomware is best achieved through monitoring anomalies in system behavior, as traditional signature-based detection may be ineffective against unknown threats.
While periodic security training helps users identify initial attack vectors like phishing, a "new type" of ransomware may bypass user vigilance or exploit system vulnerabilities directly, making anomaly detection more effective once it's active.
Use of integrated patch deployment tools addresses known vulnerabilities, but it does not provide detection capabilities for a *new* type of ransomware that might exploit zero-days or use novel attack methods.
Regular review of the threat landscape helps in proactive defense planning but does not directly enable the real-time detection of an active infection by a new malware variant.
Monitoring for anomalies in system behavior involves detecting deviations from established baselines of normal activity, such as unusual file access patterns, sudden encryption of multiple files, or unexpected network communications. This method is highly effective for identifying novel threats like new ransomware variants that may not have known signatures, allowing for early detection and response.
Concept tested: Anomaly detection for unknown threats
Source: https://learn.microsoft.com/en-us/security/operations/security-monitoring-overview
Topics
Community Discussion
No community discussion yet for this question.