FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A bank's security operations center detects that ransomware is encrypting file servers in a regional office. Which action should the incident response plan prioritize first?
The first priority is containment: isolating affected systems from the network to stop the ransomware spreading. Restoring before isolation risks reinfecting clean systems, and public communication and disciplinary steps follow once the scope and facts are established.
- AContain the affected systems by isolating them from the network to prevent further spreadCorrect
- BPublish a public statement describing the root cause of the attack
- CRestore all servers from backup immediately before isolating them
- DBegin disciplinary action against the employee who opened the phishing email
Explanation
Containment limits the spread and damage once an incident is detected and confirmed. Restoring before isolation risks reinfection of the restored systems. Public statements and disciplinary action come later, after facts are established.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A regional bank's security team observes that a group has gained access to its payment-messaging environment, remained undetected for severa…
- Which development is most consistent with the view that the cyber threat landscape for financial institutions is evolving?
- After a breach, a review finds that the bank's security tools generated alerts about unusual data transfers for several weeks, but the alert…
- A bank's security team detects ransomware spreading across several file servers. Under a standard incident response lifecycle, which action …
- A firm estimates a cyber event that compromises customer data has an annual probability of 4%, and a loss of USD 25 million if it occurs. A …
- A retail bank discovers that attackers entered through a vendor's remote-access credentials, moved laterally across its flat internal networ…