Question 1 of 30
Research into a critical ransomware incident reveals that the incident response team lead, upon initial detection, is unsure of the exact steps to take for containment and eradication, as the team members have varying levels of experience and the incident response plan is not readily accessible. The CISO is available but is currently engaged in high-level discussions with the board. What is the most appropriate immediate course of action for the incident response team lead to ensure an effective and compliant response?
Immediately initiate a structured communication with the incident response team, referencing any available documentation or known best practices for ransomware containment, and delegate initial containment actions based on perceived expertise while prioritizing the search for and activation of the formal incident response plan.
Bypass the incident response team lead and directly contact the CISO to request detailed, step-by-step instructions for every action the team should take.
Instruct each incident response team member to independently assess the situation and take whatever immediate actions they deem necessary to stop the spread of the ransomware.
Focus exclusively on technical remediation efforts to restore systems to their pre-incident state, deferring any communication or coordination with other departments until the technical issues are fully resolved.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free