Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

A bank's security team detects ransomware spreading across several file servers. Under a standard incident response lifecycle, which action should be taken first once the incident has been confirmed?

The first action is containment: isolate the affected systems to stop the ransomware spreading while preserving forensic evidence. Restoration, public disclosure and risk register updates come later, because restoring before containment risks reinfection and root cause is not yet known.

  1. AContain the spread by isolating affected systems from the network while preserving evidenceCorrect
  2. BRestore all encrypted servers from the latest backup immediately
  3. CPublish a full public disclosure of the root cause
  4. DUpdate the risk register to reduce the likelihood rating of ransomware

Explanation

After detection and confirmation, the priority is containment to stop further damage, while preserving forensic evidence. Restoring before containment risks reinfection, and root-cause disclosure and risk register updates belong to later lessons-learned stages.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions