nerdexam
Network_Appliance

NS0-304 · Question #3

ONTAP's Autonomous Anti-ransomware engine reports a potential ransomware attack. The administrator finds the majority of the files appear encrypted and disables the share. What should the…

The correct answer is B. Perform a SnapRestore using the weekly snapshot and re-enable the share. When dealing with a potential ransomware attack where files appear encrypted, it is crucial to restore the affected data to a point before the corruption occurred. The best course of action in this scenario is to perform a SnapRestore using a known good weekly snapshot and then…

Hybrid cloud data protection

Question

ONTAP's Autonomous Anti-ransomware engine reports a potential ransomware attack. The administrator finds the majority of the files appear encrypted and disables the share. What should the administrator do to minimize data loss?

Options

  • ACreate a FlexClone using the locked snapshot and re-enable the share
  • BPerform a SnapRestore using the weekly snapshot and re-enable the share
  • CRehost the volume to a different SVM and create a new share
  • DTake a manual snapshot and re-enable the share

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    77% (17)
  • C
    14% (3)
  • D
    5% (1)

Explanation

When dealing with a potential ransomware attack where files appear encrypted, it is crucial to restore the affected data to a point before the corruption occurred. The best course of action in this scenario is to perform a SnapRestore using a known good weekly snapshot and then re- enable the share. Assess the Snapshots: Verify that you have snapshots that predate the ransomware attack. These snapshots should be intact and free from encryption or corruption. Perform a SnapRestore: Use the SnapRestore operation to quickly revert the entire volume to the state captured in the selected weekly snapshot. SnapRestore is efficient because it does not involve data movement; it simply reverts pointers in the filesystem. Re-enable the Share: After successfully reverting the volume to a good state, the share can be safely re-enabled, allowing users to access the clean, restored data. Verify System Integrity and Security: Before re-enabling the share, ensure that all system vulnerabilities are addressed to prevent future attacks. Implement improved security measures as needed.

Topics

#Autonomous Anti-ransomware#SnapRestore#ransomware recovery#snapshot

Community Discussion

No community discussion yet for this question.

Full NS0-304 Practice