exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 173 discussion

Actual exam question from CompTIA's CS0-003
Question #: 173
Topic #: 1
[All CS0-003 Questions]

Which of following would best mitigate the effects of a new ransomware attack that was not properly stopped by the company antivirus?

  • A. Install a firewall.
  • B. Implement vulnerability management.
  • C. Deploy sandboxing.
  • D. Update the application blocklist.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
FT000
Highly Voted 10 months, 3 weeks ago
Selected Answer: C
I would go with C too as sandboxing is the only 'mitigating control' from the given options. The rest look to me as 'preventive controls'.
upvoted 10 times
JAlexander35
5 months, 3 weeks ago
What is sandboxing mitigating if the breach has already occured?
upvoted 3 times
...
captaintoadyo
8 months, 1 week ago
Sandboxing involves isolating potentially harmful files or programs in a secure environment to analyze their behavior without risking damage to the main system. In the context of the scenario provided, where a ransomware attack has already breached the company's defenses, implementing sandboxing may help prevent future attacks by better understanding how malware behaves. However, in the immediate aftermath of an attack, addressing vulnerabilities through vulnerability management (option B) would likely have a more immediate impact on mitigating the effects and preventing similar incidents in the future
upvoted 4 times
...
...
johnabayot
Highly Voted 10 months, 1 week ago
Selected Answer: B
B. Implement vulnerability management. This is because vulnerability management is a process of identifying, assessing, and remediating security weaknesses in systems and applications that could be exploited by malicious actors1. By implementing vulnerability management, an organization can reduce the attack surface and prevent ransomware from spreading or encrypting more data.
upvoted 5 times
TurboMor
4 months, 2 weeks ago
So... if you have an active ransomware attack in your organization, you are going to prefer starting the process of vulnerability management to attempt to prevent other systems from getting encrypted, rather than updating the application blocklist to immediately block the encryption binary? I would definitely update the blocklist first and then think about assessing and remediating vulnerabilities.
upvoted 2 times
...
...
Popeyes_Chicken
Most Recent 4 days, 16 hours ago
Selected Answer: D
If a ransomware attack has already made it past the company antivirus. Implementing vulnerability management during a ransomware attack or installing a firewall doesn't seem to be the best option. Sandboxing might stop some lateral movement but doesn't guarantee it will mitigate the programs ability to run on other machines. Finding the ransomware program and adding it to an application block list ensures the application can't run / move laterally. Which will mitigate an active attack, instead of hoping a sandbox will stop it. Which it won't.
upvoted 1 times
...
hashed_pony
2 months, 3 weeks ago
This is one of those questions where all the answers seem not good enough. All of these measures are preventative when we're looking for corrective measures when the problem is already there.
upvoted 1 times
...
cy_analyst
2 months, 4 weeks ago
Selected Answer: B
So actually this question is rhetorical and wants to know what the company should have done to prevent a future event of a ransomware attack.
upvoted 1 times
...
Serac
3 months ago
Selected Answer: D
I’m thinking in term of prioritising isolation/containment first. Blocking the malware from running on other still clean systems would limit the damage. But I could argue that running a sandbox to better understand the malware to block it better is also reasonable. But that cost more time, so I’m going with D. Feeling almost 50/50 between them.
upvoted 1 times
...
TurboMor
4 months, 2 weeks ago
Selected Answer: D
Updating the application blocklist can immediately block the ransomware binaries on the rest of systems, making it the best option to mitigate the effects of a materialized ransomware attack.
upvoted 4 times
...
crackman123
4 months, 2 weeks ago
Selected Answer: D
pdating the application blocklist directly addresses and contains the active ransomware, preventing its execution and reducing its impact.
upvoted 4 times
TurboMor
4 months, 2 weeks ago
Thank you. I was starting to believe I was alone on this one. Completely agree with this answer.
upvoted 3 times
...
...
Odogwu3024
4 months, 3 weeks ago
I believe sandbox is strictly for testing
upvoted 1 times
...
Omo_Mushin
5 months, 3 weeks ago
The best option to mitigate the effects of a new ransomware attack that was not properly stopped by the company's antivirus would be: C. Deploy sandboxing. Sandboxing allows you to run potentially malicious files or programs in an isolated environment where they cannot affect the rest of the system. This way, even if ransomware manages to get past the antivirus, its ability to cause harm would be limited to the sandboxed environment.
upvoted 2 times
...
Dub3
7 months, 3 weeks ago
Selected Answer: C
While options like installing a firewall (A), implementing vulnerability management (B), and updating the application blocklist (D) are important security measures, they may not directly address the immediate threat posed by the ransomware attack. Sandboxing provides a proactive defense mechanism specifically designed to detect and mitigate the effects of malware, including ransomware, by analyzing its behavior in a controlled environment.
upvoted 4 times
...
[Removed]
10 months, 3 weeks ago
Sandboxing seems like the best answer here, it's the only post infection persciption from what I can see. We need to mitigate it after it already beat the firewall making the other options questionable.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago