SC-100 · Question #135
Drag and Drop Question Your company wants to optimize ransomware incident investigations. You need to recommend a plan to investigate ransomware incidents based on the Microsoft Detection and…
The correct answer is Assess the current situation and identify the scope.; Identify which line-of-business (LOB) apps are unavailable due to a ransomware incident.; Identify the compromise recovery process.; Implement a comprehensive strategy to reduce the risk of privileged access compromise.; Update organizational processes to manage major ransomware events and streamline outsourcing to avoid friction. The correct sequence of actions for investigating ransomware incidents, according to the Microsoft DART approach, involves first assessing the situation and scope, then identifying business impact, and finally planning the recovery process.
Question
Exhibits
Answer Area
Drag items
Correct arrangement
- Assess the current situation and identify the scope.
- Identify which line-of-business (LOB) apps are unavailable due to a ransomware incident.
- Identify the compromise recovery process.
- Implement a comprehensive strategy to reduce the risk of privileged access compromise.
- Update organizational processes to manage major ransomware events and streamline outsourcing to avoid friction.
Explanation
The correct sequence of actions for investigating ransomware incidents, according to the Microsoft DART approach, involves first assessing the situation and scope, then identifying business impact, and finally planning the recovery process.
Approach. The correct interaction involves dragging three specific actions from the 'Actions' list to the 'Answer Area' and arranging them in the following order:
- Assess the current situation and identify the scope. - This is the critical first step in any incident response. Before any specific actions can be taken, it's essential to understand the nature, extent, and impact of the ransomware attack. This aligns with the 'Detection and Analysis' phase of incident response, establishing the foundational understanding for all subsequent steps.
- Identify which line-of-business (LOB) apps are unavailable due to a ransomware incident. - Once the overall situation and scope are assessed, the next logical step is to determine the business impact. Identifying affected LOB applications helps prioritize recovery efforts, understand operational disruption, and communicate effectively with stakeholders. This is a crucial part of the 'Analysis' phase, focusing on impact assessment.
- Identify the compromise recovery process. - After understanding the scope and specific business impacts (i.e., which critical LOB apps are down), the final step in this sequence is to determine how to recover. This involves developing a detailed plan for restoring systems, data, and services, directly leading into the 'Recovery' phase of incident response. This step cannot be effectively performed without the preceding assessment and impact analysis.
Common mistakes.
- common_mistake. Common mistakes often involve selecting actions that are either proactive/preventative measures or post-incident improvements, rather than steps specific to an active incident investigation and response. For instance, 'Implement a comprehensive strategy to reduce the risk of privileged access compromise' is a preventative security measure, not part of an active incident investigation. Similarly, 'Update organizational processes to manage major ransomware events and streamline outsourcing to avoid friction' is a post-incident lesson learned or pre-incident preparation activity aimed at future improvements, not an immediate step in responding to a current ransomware incident. Including these options would demonstrate a misunderstanding of the incident response lifecycle and the specific context of an ongoing investigation.
Concept tested. Incident response methodology, specifically for ransomware incidents, including the phases of detection, analysis, and recovery planning, often aligned with frameworks like the Microsoft Detection and Response Team (DART) approach or NIST incident response lifecycle.
Topics
Community Discussion
No community discussion yet for this question.

