CRISC · Question #508
An organization has established a policy prohibiting ransom payments if subjected to a ransomware attack. Which of the following is the MOST effective control to support this policy?
The correct answer is B. Creating immutable backups. To effectively support a policy prohibiting ransom payments in a ransomware attack, creating immutable backups is the most effective control. Immutable backups ensure data cannot be altered or deleted, enabling recovery without paying the ransom.
Question
An organization has established a policy prohibiting ransom payments if subjected to a ransomware attack. Which of the following is the MOST effective control to support this policy?
Options
- AConducting periodic vulnerability scanning
- BCreating immutable backups
- CPerforming required patching
- DImplementing continuous intrusion detection monitoring
How the community answered
(35 responses)- A14% (5)
- B74% (26)
- C9% (3)
- D3% (1)
Why each option
To effectively support a policy prohibiting ransom payments in a ransomware attack, creating immutable backups is the most effective control. Immutable backups ensure data cannot be altered or deleted, enabling recovery without paying the ransom.
Conducting periodic vulnerability scanning helps identify weaknesses that could lead to an attack, but it doesn't provide a recovery mechanism *after* a successful ransomware encryption, which is the direct counter to paying a ransom.
Creating immutable backups is the most effective control to support a policy against paying ransomware. Immutable backups cannot be modified, encrypted, or deleted by attackers, even if they gain administrative access. This allows an organization to restore its data and systems to a pre-attack state without having to engage with threat actors or pay a ransom, directly enabling the "no ransom payment" policy.
Performing required patching mitigates known vulnerabilities and reduces the attack surface, preventing some ransomware attacks, but it doesn't provide a recovery option once systems are encrypted.
Implementing continuous intrusion detection monitoring helps detect active attacks, potentially allowing for containment before widespread encryption, but it does not guarantee recovery or negate the need for a ransom payment if encryption is successful.
Concept tested: Ransomware recovery controls
Source: https://learn.microsoft.com/en-us/azure/backup/backup-immutable-vault
Topics
Community Discussion
No community discussion yet for this question.