nerdexam
(ISC)2

CISSP · Question #1508

The Chief Information Security Officer (CISO) is concerned about business application availability. The organization was recently subject to a ransomware attack that resulted in the unavailability of

The correct answer is A. Virtualization. After a ransomware attack caused 10 days of downtime, the organization needs a solution that improves Recovery Time Objective (RTO) and enables more frequent data snapshots/backups. Virtualization directly addresses both requirements through VM snapshots, rapid provisioning, and

Submitted by suresh_in· Mar 5, 2026Security Operations

Question

The Chief Information Security Officer (CISO) is concerned about business application availability. The organization was recently subject to a ransomware attack that resulted in the unavailability of applications and services for 10 working days that required paper-based running of all main business processes. There are now aggressive plans to enhance the Recovery Time Objective (RTO) and cater for more frequent data captures. Which of the following solutions should be implemented to fully comply to the new business requirements?

Options

  • AVirtualization
  • BAntivirus
  • CProcess isolation
  • DHost-based intrusion prevention system (HIPS)

How the community answered

(28 responses)
  • A
    71% (20)
  • B
    4% (1)
  • C
    18% (5)
  • D
    7% (2)

Why each option

After a ransomware attack caused 10 days of downtime, the organization needs a solution that improves Recovery Time Objective (RTO) and enables more frequent data snapshots/backups. Virtualization directly addresses both requirements through VM snapshots, rapid provisioning, and live migration capabilities.

AVirtualizationCorrect

Virtualization enables rapid recovery through VM snapshots (frequent point-in-time data captures), live migration, and the ability to quickly spin up new virtual instances from clean snapshots, dramatically reducing RTO from days to hours or minutes. Virtual environments also support replication to secondary sites and easy rollback to pre-attack states, directly addressing both the RTO improvement goal and the need for more frequent data captures.

BAntivirus

Antivirus is a preventative control that detects and removes malware but does not improve RTO or provide mechanisms for frequent data captures or rapid system restoration after an attack.

CProcess isolation

Process isolation is a security technique that limits the blast radius of a compromised process but does not address recovery time objectives or provide data capture/backup capabilities needed after a ransomware event.

DHost-based intrusion prevention system (HIPS)

A Host-based Intrusion Prevention System (HIPS) monitors and blocks suspicious activity on endpoints as a preventative and detective control, but it provides no functionality for improving recovery time or enabling frequent data snapshots.

Concept tested: Virtualization for business continuity and RTO improvement

Source: https://learn.microsoft.com/en-us/azure/site-recovery/site-recovery-overview

Topics

#recovery time objective#ransomware recovery#virtualization#business continuity

Community Discussion

No community discussion yet for this question.

Full CISSP Practice