exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 64 discussion

Actual exam question from CompTIA's CS0-002
Question #: 64
Topic #: 1
[All CS0-002 Questions]

A security analyst is handling an incident in which ransomware has encrypted the disks of several company workstations. Which of the following would work BEST to prevent this type of incident in the future?

  • A. Implement a UTM instead of a stateful firewall and enable gateway antivirus.
  • B. Back up the workstations to facilitate recovery and create a gold image.
  • C. Establish a ransomware awareness program and implement secure and verifiable backups.
  • D. Virtualize all the endpoints with daily snapshots of the virtual machines.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TheStudiousPeepz
Highly Voted 2 years, 11 months ago
All of you are wrong. The answer is C. What if the ransomeware is transmitted through a plugged in USB? Can't be A. Many people in the discussions for these questions after 200 are wrong. Don't follow the sheep
upvoted 16 times
absabs
2 years, 4 months ago
it make sense..
upvoted 3 times
...
...
zhuzhu123
Most Recent 1 year, 7 months ago
Selected Answer: A
An UTM can also include an IPS and endpoint protection, this would cover an USB stick attack and with the IPS prevent the same happening again. Therefore I vote for A
upvoted 1 times
...
32d799a
1 year, 7 months ago
Selected Answer: C
While all the options may contribute to overall security, option C is the most comprehensive and directly addresses the prevention of ransomware incidents
upvoted 2 times
...
2Fish
2 years, 3 months ago
Selected Answer: C
C is correct. Users are a huge part of ransomeware launches. So User awareness is key. Backups that are verifiable and can actually be restored is the biggest part of recovering from a ransomeware attack.
upvoted 2 times
...
AaronS1990
2 years, 4 months ago
Selected Answer: C
As far as CompTIA are concerned backups are the best mitigation against ransomware. Throw in the employee training too and you've got your answer.
upvoted 2 times
...
catastrophie
2 years, 5 months ago
C is correct. It's the only option that consist of a prevention and a recovery method. Employees can be trained to recognize and avoid potential threats, such as not clicking on suspicious links or attachments. Implementing secure and verifiable backups (preferably those in option B the gold image) also ensures that the company has a way to restore their data in the event of an attack. Option A does nothing for recovery if it fails to protect the systems. Option D is the polar opposite of A, it is great for recover but does nothing for prevention.
upvoted 1 times
...
CyberNoob404
2 years, 5 months ago
Selected Answer: C
People are always the weakest link. Must train them. This also includes backup solution.
upvoted 3 times
...
anap2022
2 years, 8 months ago
Selected Answer: C
C is the best answer. I currently work in a SOC and we talk about ransomware quite often. Training and awareness is always the first thing to do. For example to pick up random USB's laying around and connect them to your computer.
upvoted 2 times
...
Jimmycyber123
2 years, 8 months ago
Selected Answer: C
This isn't up for debate. The answer is C. Anyone saying otherwise is wrong
upvoted 3 times
...
jagoichi
2 years, 8 months ago
Selected Answer: C
Agree C Training and awareness is always the BEST answer
upvoted 1 times
...
MortG7
2 years, 8 months ago
Awareness training and having a good backup is the only way to recover from ransomware...or get yourself some good ole Bitcoin for payment to retrieve the keys (if you are Lucky)..for me, C is best
upvoted 2 times
...
ryanzou
2 years, 8 months ago
Selected Answer: C
C makes more sense.
upvoted 3 times
...
sh4dali
2 years, 9 months ago
Selected Answer: C
I have to go with C. It's the user awareness that prevents it.
upvoted 3 times
...
Fastytop
2 years, 9 months ago
Selected Answer: A
UTM.. of course.
upvoted 1 times
...
Adonist
2 years, 10 months ago
Selected Answer: C
I agree with C. Most companies that are affected by Ransomware have firewalls and antivirus lol
upvoted 2 times
...
Laudy
2 years, 10 months ago
Selected Answer: A
Only one that PREVENTS.
upvoted 2 times
forklord72
2 years, 8 months ago
This does not prevent, this mitigates the effects. The only answer that can possibly prevent is C
upvoted 1 times
...
...
miabe
2 years, 11 months ago
Selected Answer: C
looks good to me
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...