CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security
A company detects ransomware encrypting files on one finance-department server connected to the corporate network. The incident team must act first to preserve evidence and limit spread. Which sequence is most appropriate?
The best sequence is to isolate the affected server from the network without abrupt power-off, capture volatile memory and logs as evidence, and then eradicate and recover. Wiping first or deleting files destroys forensic evidence, and paying the ransom does not contain the incident.
- AWipe and reinstall the server, then collect logs from the rebuilt system
- BIsolate the server from the network without powering it off abruptly, capture volatile memory and logs, then proceed to eradication and recoveryCorrect
- CPay the ransom immediately to recover files, then investigate
- DShut down all servers company-wide and delete suspicious files before taking images
Explanation
Containment by network isolation stops lateral spread, while keeping the machine running allows capture of volatile memory and logs that serve as evidence. Wiping first destroys evidence and deleting files before imaging corrupts the forensic trail. Paying a ransom is not a containment step and does not preserve evidence.
Did you get it right without looking?
One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.
More Cyber Security questions
- The website of a Chennai online ticketing company becomes unreachable on a sale day because thousands of compromised devices spread across m…
- Employees of a Pune logistics firm receive an email that appears to come from the company's CEO, with a link to a page that imitates the cor…
- A Mumbai company's employee finds her files unreadable and a message demanding payment in cryptocurrency for a decryption key. Investigation…
- An attacker enters the string ' OR '1'='1 into the login field of a company's web portal and gains access without a valid password, because …
- Under the CERT-In Directions of 2022, for how long must logs of all ICT systems be maintained securely, within the Indian jurisdiction?
- Under the IT Act, 2000, which of the following is the legal function of a digital signature certificate issued by a Certifying Authority?