nerdexam
Isaca

CRISC · Question #508

An organization has established a policy prohibiting ransom payments if subjected to a ransomware attack. Which of the following is the MOST effective control to support this policy?

The correct answer is B. Creating immutable backups. To effectively support a policy prohibiting ransom payments in a ransomware attack, creating immutable backups is the most effective control. Immutable backups ensure data cannot be altered or deleted, enabling recovery without paying the ransom.

Submitted by helene.fr· Apr 18, 2026Risk Response and Reporting

Question

An organization has established a policy prohibiting ransom payments if subjected to a ransomware attack. Which of the following is the MOST effective control to support this policy?

Options

  • AConducting periodic vulnerability scanning
  • BCreating immutable backups
  • CPerforming required patching
  • DImplementing continuous intrusion detection monitoring

How the community answered

(35 responses)
  • A
    14% (5)
  • B
    74% (26)
  • C
    9% (3)
  • D
    3% (1)

Why each option

To effectively support a policy prohibiting ransom payments in a ransomware attack, creating immutable backups is the most effective control. Immutable backups ensure data cannot be altered or deleted, enabling recovery without paying the ransom.

AConducting periodic vulnerability scanning

Conducting periodic vulnerability scanning helps identify weaknesses that could lead to an attack, but it doesn't provide a recovery mechanism *after* a successful ransomware encryption, which is the direct counter to paying a ransom.

BCreating immutable backupsCorrect

Creating immutable backups is the most effective control to support a policy against paying ransomware. Immutable backups cannot be modified, encrypted, or deleted by attackers, even if they gain administrative access. This allows an organization to restore its data and systems to a pre-attack state without having to engage with threat actors or pay a ransom, directly enabling the "no ransom payment" policy.

CPerforming required patching

Performing required patching mitigates known vulnerabilities and reduces the attack surface, preventing some ransomware attacks, but it doesn't provide a recovery option once systems are encrypted.

DImplementing continuous intrusion detection monitoring

Implementing continuous intrusion detection monitoring helps detect active attacks, potentially allowing for containment before widespread encryption, but it does not guarantee recovery or negate the need for a ransom payment if encryption is successful.

Concept tested: Ransomware recovery controls

Source: https://learn.microsoft.com/en-us/azure/backup/backup-immutable-vault

Topics

#Ransomware#Immutable Backups#Incident Recovery#Risk Response Controls

Community Discussion

No community discussion yet for this question.

Full CRISC Practice