CISSP · Question #1508
The Chief Information Security Officer (CISO) is concerned about business application availability. The organization was recently subject to a ransomware attack that resulted in the unavailability of
The correct answer is A. Virtualization. After a ransomware attack caused 10 days of downtime, the organization needs a solution that improves Recovery Time Objective (RTO) and enables more frequent data snapshots/backups. Virtualization directly addresses both requirements through VM snapshots, rapid provisioning, and
Question
The Chief Information Security Officer (CISO) is concerned about business application availability. The organization was recently subject to a ransomware attack that resulted in the unavailability of applications and services for 10 working days that required paper-based running of all main business processes. There are now aggressive plans to enhance the Recovery Time Objective (RTO) and cater for more frequent data captures. Which of the following solutions should be implemented to fully comply to the new business requirements?
Options
- AVirtualization
- BAntivirus
- CProcess isolation
- DHost-based intrusion prevention system (HIPS)
How the community answered
(28 responses)- A71% (20)
- B4% (1)
- C18% (5)
- D7% (2)
Why each option
After a ransomware attack caused 10 days of downtime, the organization needs a solution that improves Recovery Time Objective (RTO) and enables more frequent data snapshots/backups. Virtualization directly addresses both requirements through VM snapshots, rapid provisioning, and live migration capabilities.
Virtualization enables rapid recovery through VM snapshots (frequent point-in-time data captures), live migration, and the ability to quickly spin up new virtual instances from clean snapshots, dramatically reducing RTO from days to hours or minutes. Virtual environments also support replication to secondary sites and easy rollback to pre-attack states, directly addressing both the RTO improvement goal and the need for more frequent data captures.
Antivirus is a preventative control that detects and removes malware but does not improve RTO or provide mechanisms for frequent data captures or rapid system restoration after an attack.
Process isolation is a security technique that limits the blast radius of a compromised process but does not address recovery time objectives or provide data capture/backup capabilities needed after a ransomware event.
A Host-based Intrusion Prevention System (HIPS) monitors and blocks suspicious activity on endpoints as a preventative and detective control, but it provides no functionality for improving recovery time or enabling frequent data snapshots.
Concept tested: Virtualization for business continuity and RTO improvement
Source: https://learn.microsoft.com/en-us/azure/site-recovery/site-recovery-overview
Topics
Community Discussion
No community discussion yet for this question.