CompTIA CySA+ (CS0-003)Reporting and CommunicationEasy

A security analyst is conducting a post-incident review for a successful ransomware attack. The 'lessons learned' report needs to highlight areas for improving the organization's resilience. Which of the following would be the MOST critical metric to analyze and potentially improve for future incident recovery?

  1. AMean Time To Recover (MTTR) affected systems and data.
  2. BMean Time To Detect (MTTD) the initial intrusion.
  3. CNumber of security awareness training modules completed by employees.
  4. DMean Time To Contain (MTTC) the ransomware spread.
Show answer & explanation

Correct answer: A. Mean Time To Recover (MTTR) affected systems and data.

For a successful ransomware attack, the primary goal after containment is recovery. MTTR (Mean Time To Recover) directly measures how quickly affected systems and data can be restored to normal operations, which is crucial for improving organizational resilience against such attacks.

Why the other options are wrong

  • B. MTTD is important for early detection but doesn't directly measure recovery effectiveness after a successful attack.
  • C. Security awareness training is a preventative measure, not a direct metric for post-attack recovery resilience.
  • D. MTTC is critical for stopping the spread, but the question focuses on improving resilience for *recovery* after a successful attack.

Ransomware Recovery Metrics

Metrics used to evaluate and improve the organization's ability to restore operations and data after a ransomware attack.

  • Focus on recovery time objectives (RTO) and recovery point objectives (RPO).
  • MTTR is a key indicator of recovery efficiency.
  • Essential for business continuity and resilience.

Memory trick: After ransomware, the goal is to RECOVER and get back to NORMAL operation.

More Reporting and Communication questions