exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 76 discussion

Actual exam question from CompTIA's CAS-004
Question #: 76
Topic #: 1
[All CAS-004 Questions]

Ransomware encrypted the entire human resources fileshare for a large financial institution. Security operations personnel were unaware of the activity until it was too late to stop it. The restoration will take approximately four hours, and the last backup occurred 48 hours ago. The management team has indicated that the
RPO for a disaster recovery event for this data classification is 24 hours.
Based on RPO requirements, which of the following recommendations should the management team make?

  • A. Leave the current backup schedule intact and pay the ransom to decrypt the data.
  • B. Leave the current backup schedule intact and make the human resources fileshare read-only.
  • C. Increase the frequency of backups and create SIEM alerts for IOCs.
  • D. Decrease the frequency of backups and pay the ransom to decrypt the data.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
bobsmith69
6 months, 3 weeks ago
Selected Answer: C
C is the only option that would work
upvoted 1 times
...
BiteSize
9 months, 3 weeks ago
Selected Answer: C
The only option listed that will increase the logs from 48 hours to the 24 hours being asked. -Simple as that Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 1 times
...
p1s3c
1 year ago
C Based on the RPO requirements, the management team should recommend increasing the frequency of backups and creating SIEM alerts for IOCs. The RPO (Recovery Point Objective) for the human resources fileshare is 24 hours, which means that the organization needs to be able to recover the data up to 24 hours before the ransomware attack occurred. Since the last backup occurred 48 hours ago, the organization is not meeting its RPO requirement. Increasing the frequency of backups will allow the organization to meet its RPO requirement and minimize data loss in the event of another ransomware attack. Creating SIEM alerts for IOCs (Indicators of Compromise) will also help the organization detect and respond to future attacks more quickly. Paying the ransom should not be considered as a recommended option since it does not guarantee the recovery of the data and may encourage further attacks. Making the fileshare read-only would also not be a recommended option since it would not address the issue of data loss.
upvoted 3 times
...
AnnoyingIAGuy
1 year, 3 months ago
Selected Answer: C
C is the best answer
upvoted 2 times
...
Mr_BuCk3th34D
1 year, 4 months ago
Selected Answer: C
It is not advisable to pay the ransom in a ransomware attack, as this only encourages the attackers and does not guarantee that the data will actually be decrypted. Instead, the management team should consider increasing the frequency of backups to meet the RPO requirements for the human resources fileshare. Additionally, implementing SIEM alerts for indicators of compromise (IOCs) can help to detect and prevent future ransomware attacks.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago