Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

A bank's security operations center detects that ransomware is encrypting file servers in a regional office. Which action should the incident response plan prioritize first?

The first priority is containment: isolating affected systems from the network to stop the ransomware spreading. Restoring before isolation risks reinfecting clean systems, and public communication and disciplinary steps follow once the scope and facts are established.

  1. AContain the affected systems by isolating them from the network to prevent further spreadCorrect
  2. BPublish a public statement describing the root cause of the attack
  3. CRestore all servers from backup immediately before isolating them
  4. DBegin disciplinary action against the employee who opened the phishing email

Explanation

Containment limits the spread and damage once an incident is detected and confirmed. Restoring before isolation risks reinfection of the restored systems. Public statements and disciplinary action come later, after facts are established.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions