Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security

A company detects ransomware encrypting files on one finance-department server connected to the corporate network. The incident team must act first to preserve evidence and limit spread. Which sequence is most appropriate?

The best sequence is to isolate the affected server from the network without abrupt power-off, capture volatile memory and logs as evidence, and then eradicate and recover. Wiping first or deleting files destroys forensic evidence, and paying the ransom does not contain the incident.

  1. AWipe and reinstall the server, then collect logs from the rebuilt system
  2. BIsolate the server from the network without powering it off abruptly, capture volatile memory and logs, then proceed to eradication and recoveryCorrect
  3. CPay the ransom immediately to recover files, then investigate
  4. DShut down all servers company-wide and delete suspicious files before taking images

Explanation

Containment by network isolation stops lateral spread, while keeping the machine running allows capture of volatile memory and logs that serve as evidence. Wiping first destroys evidence and deleting files before imaging corrupts the forensic trail. Paying a ransom is not a containment step and does not preserve evidence.

Did you get it right without looking?

One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.

More Cyber Security questions