CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium

An organization experiences a widespread ransomware attack that encrypts critical servers and workstations. The security team successfully contains the outbreak by segmenting networks. They've identified the initial vector and eradicated the malware. What is the MOST critical next step in the incident response lifecycle to ensure business continuity and prevent recurrence?

  1. AConduct a full vulnerability scan of all network devices.
  2. BRevise the incident response plan based on lessons learned.
  3. CRestore affected systems from verified clean backups.
  4. DUpdate all antivirus definitions and perform full system scans.
Show answer & explanation

Correct answer: C. Restore affected systems from verified clean backups.

After containment and eradication of ransomware, restoring systems from verified clean backups is the most critical step in the recovery phase to bring operations back online and ensure business continuity.

Why the other options are wrong

  • A. Vulnerability scanning is important, but restoring operations is the immediate priority after eradication in a ransomware scenario.
  • B. Revising the IR plan is part of post-incident activity and occurs after recovery, focusing on future prevention, not immediate system restoration.
  • D. Updating antivirus definitions is part of eradication and hardening, but restoring data is necessary to recover from encryption.

Recovery Phase

The incident response phase focused on restoring affected systems and services to normal operation.

  • Occurs after eradication.
  • Aims to ensure business continuity.
  • Often involves restoring from backups.

Memory trick: After the fire, rebuild and bring everything back online.

More Incident Response and Management questions