An organization has received complaints from users that some of their files have been encrypted. These users are receiving demands for money to decrypt the files. Which of the following would be the BEST course of action?
C - Initiate Incident response-. The question mentions "course of action" not a single stage in incident response. Moreover, Containment (isolating affected systems) is part of the Incident response course of action
It's a ransomware infection = incident (and a pretty large one, I may add). Ergo initiate incident response. Incident response would encompass isolation during containment phase.
It is C, too many people are focused on just one aspect being A which is isolation. Isolating the systems is a part of the incident response as well as several other necessary steps.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
pgonza
2 months, 3 weeks agoAlexJacobson
9 months, 3 weeks agoblehbleh
10 months, 2 weeks agoenk
11 months, 2 weeks agoUncle_Lucifer
11 months, 2 weeks agoideu
1 year agoUncle_Lucifer
11 months, 2 weeks agoUncle_Lucifer
11 months, 2 weeks agorichck102
1 year, 4 months ago