Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 303 discussion

Actual exam question from Isaca's CISM
Question #: 303
Topic #: 1
[All CISM Questions]

To prevent ransomware attacks, it is MOST important to ensure:

  • A. adequate backup and restoration processes are in place.
  • B. regular security awareness training is conducted.
  • C. the latest security appliances are installed.
  • D. updated firewall software is installed.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Ziggybooboo
Highly Voted 2 years ago
Backups don't prevent attacks, I would go with security awareness
upvoted 17 times
[Removed]
1 year, 4 months ago
neither does security awareness prevent ransomware
upvoted 1 times
...
...
Funshykay
Highly Voted 1 year, 10 months ago
Selected Answer: B
I will go with B. the question does not state to recover from ransomware attack but to prevent. I can't figure out how data backup and restoration process helps stop a ransomware attack from happening
upvoted 10 times
...
Jess20
Most Recent 3 weeks, 3 days ago
Selected Answer: B
Prevent! A.
upvoted 1 times
Jess20
3 weeks, 3 days ago
B. ****
upvoted 1 times
...
...
david124
1 month ago
Selected Answer: B
HOW, HOW does having backups prevent a ransomware? IT great to have backups sure, no down time. BUT training your users so they dont F around helps reduce ransomware
upvoted 1 times
...
Y0GA
6 months ago
GPT first gave me A. however, if you reiterate the input and tell it that the question is asking about 'prevention', GPT will go with B. it really depends on what ISACA is referring to with the words 'prevent' and 'ransomware attack'. a successful ransomware would already require mitigation via backups. but prior to that, we are talking about preventive measures for potential attacks. they are being tricky with the wording but i think we have to read it as literally as possible.
upvoted 1 times
...
helg420
6 months, 1 week ago
Selected Answer: B
B: To effectively prevent ransomware attacks from occurring in the first place, the focus should indeed be on preventative measures i.e. Security Awareness. Backup and restoration processes are primarily corrective controls rather than preventative and will help with mitigating the impact.
upvoted 1 times
...
03allen
6 months, 1 week ago
Selected Answer: A
Backup is a prevention as well. It says most importantly, what if staff had training but still failed on a phishing attack. If you don't have a backup, you have to pay the ransom.
upvoted 1 times
99670d9
6 months, 1 week ago
Backup and restoration are both corrective controls and are not preventive. B in this case is the only preventive measure
upvoted 1 times
...
...
Thavee
7 months, 1 week ago
Selected Answer: B
To prevent! Among four choices, awareness is the only answer even if it will help just only 10%. Backup/Restore do not prevent any. This is English language common sense.
upvoted 1 times
...
yottabyte
8 months ago
Selected Answer: A
Having backups in isolated VLAN and also offsite backups is the way to go for Ransomware attacks.
upvoted 1 times
...
oluchecpoint
9 months, 2 weeks ago
Selected Answer: A
A. Adequate backup and restoration processes are in place. While all the options listed (A, B, C, and D) are important for a comprehensive cybersecurity strategy, having a robust backup and restoration process is crucial because it allows you to recover your data and systems in the event of a ransomware attack. Ransomware attackers often encrypt your data and demand a ransom for its release. If you have up-to-date backups that are isolated from your network, you can restore your data without paying the ransom, reducing the impact of the attack significantly.
upvoted 1 times
...
blehbleh
10 months, 1 week ago
Selected Answer: B
Its B. You are preventing the attacks by training. That is preventative. Backups are a corrective as they are used after a ransomware attack.
upvoted 1 times
...
secdoc
1 year, 1 month ago
Backup and restore is corrective, not preventative
upvoted 2 times
...
oluchecpoint
1 year, 2 months ago
A. Adequate backup and restoration processes are in place. While all the options listed (A, B, C, and D) are important for a comprehensive cybersecurity strategy, having a robust backup and restoration process is crucial because it allows you to recover your data and systems in the event of a ransomware attack. Ransomware attackers often encrypt your data and demand a ransom for its release. If you have up-to-date backups that are isolated from your network, you can restore your data without paying the ransom, reducing the impact of the attack significantly.
upvoted 1 times
...
Agamennore
1 year, 2 months ago
Selected Answer: B
The magical word is PREVENT. In order to prevent the most significant is awareness
upvoted 3 times
...
AaronS1990
1 year, 3 months ago
A is the BEST mitigation but the question doesn't ask that. B is more likely to prevent them though...
upvoted 1 times
AaronS1990
1 year, 2 months ago
A- Prevents B- Does not prevent it mitigates. However B is the MOST useful...
upvoted 1 times
Marcelus1714
8 months ago
A mitigates the consequences of ransomware, but never prevent...
upvoted 1 times
...
...
...
Akam
1 year, 3 months ago
Selected Answer: A
It's A. You can't rely on users, therefore, you need to have a backup in place because at some point users will do some actions and get affected by ransomware.
upvoted 1 times
...
[Removed]
1 year, 3 months ago
Selected Answer: B
Another Shit question, which is why I always review this site first... A. Is 100% an acceptable answer, but if we're going strictly by the book, and what's said within it, I believe B is what they want. CISM Review Manual 27th Edition: "The ultimate success of an information security program depends on the degree to which it is understood, supported, and appropriately used by everyone in the organization. Therefore, an ongoing security awareness program, which includes an initial orientation and periodic updates, is necessary."
upvoted 1 times
SilverFox
1 year ago
Please be aware that this is another made up quote from a non existent edition. This isn't the first time this user has done this. But I would go with B too.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...