FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks
A bank's security team detects ransomware spreading across several file servers. Under a standard incident response lifecycle, which action should be taken first once the incident has been confirmed?
The first action is containment: isolate the affected systems to stop the ransomware spreading while preserving forensic evidence. Restoration, public disclosure and risk register updates come later, because restoring before containment risks reinfection and root cause is not yet known.
- AContain the spread by isolating affected systems from the network while preserving evidenceCorrect
- BRestore all encrypted servers from the latest backup immediately
- CPublish a full public disclosure of the root cause
- DUpdate the risk register to reduce the likelihood rating of ransomware
Explanation
After detection and confirmation, the priority is containment to stop further damage, while preserving forensic evidence. Restoring before containment risks reinfection, and root-cause disclosure and risk register updates belong to later lessons-learned stages.
Did you get it right without looking?
One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.
More Case Study: Cyberthreats and Information Security Risks questions
- A bank experienced a data breach in which attackers exfiltrated customer records over several months. The investigation shows that a known v…
- After a breach, a review finds that the bank's security tools generated alerts about unusual data transfers for several weeks, but the alert…
- A risk manager reviews incident data showing that attackers increasingly compromise a bank's software vendor and use the vendor's trusted up…
- A bank scores three cyber controls on design effectiveness (D) and operating effectiveness (O), each as a percentage of risk reduction, and …
- A bank estimates a cyber outage of its online platform would occur once every 4 years on average. Each event would cost USD 2.4 million in l…
- A payments firm sets a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 15 minutes for its card authorizatio…