FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices
After a ransomware attack encrypts a payment processor's production systems, the firm restores from backups that were stored on the same network and were also encrypted. Which weakness in its resilience design does this most directly illustrate?
The failure shows a lack of isolated, immutable or offline backups. Because the backups sat on the same network, the ransomware encrypted them too, removing the recovery option. Good resilience design segregates backup copies so they survive a compromise of production systems.
- ALack of isolated, immutable or offline backups to support recoveryCorrect
- BInsufficient perimeter firewall rule logging
- COverly frequent employee phishing training
- DExcessive use of multi-factor authentication
Explanation
Backups reachable from the compromised network were destroyed with the primary data, so recovery failed. Resilient practice keeps copies segregated, offline or immutable. Firewall logging, training frequency and MFA do not explain the loss of recoverability.
Did you get it right without looking?
One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.
More Cyber-resilience: Range of Practices questions
- Which statement best describes why a firm's cyber-resilience framework should be designed to evolve over time?
- A bank's CISO reports to the Chief Information Officer (CIO), who also owns IT budgets and system delivery deadlines. An internal review not…
- A bank scores cyber scenarios by annual frequency and loss per event. Scenario A: frequency 0.20, loss USD 10 million. Scenario B: frequency…
- A bank hesitates to join a sector-wide cyber threat intelligence exchange because it fears that sharing details will expose it to legal and …
- A bank's board is reviewing its cyber-resilience framework. Which of the following best describes the board's appropriate role under the ran…
- A mid-sized bank hesitates to share cyber incident details with peers, citing concerns about confidentiality and reputational damage. Which …