Question 1 of 30
Market research demonstrates that a financial services firm has experienced a significant ransomware attack, encrypting customer account data and impacting critical trading systems. The Chief Information Security Officer (CISO) is under immense pressure from the CEO to restore services immediately. Which of the following actions best aligns with a compliant and effective incident response strategy?
Isolate affected network segments, deploy endpoint detection and response (EDR) tools to identify and remove the ransomware, and begin documenting all containment and eradication steps for potential regulatory reporting.
Immediately initiate data restoration from the most recent backups to bring trading systems back online, assuming the backups are clean.
Focus all available resources on crafting public statements and internal communications to manage reputational damage, deferring technical investigation until systems are operational.
Halt all system operations and initiate a complete forensic investigation before any attempt is made to contain the threat or restore services, to ensure no evidence is compromised.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free