mediumMultiple ChoiceObjective-mapped
CAS-004 Practice Question: A healthcare organization has suffered a…
A healthcare organization has suffered a ransomware attack. The ransomware encrypted all files on file servers and workstations, and a ransom note demands payment in cryptocurrency. The backup systems were also encrypted because the backup service account had write access to the backup repository. The organization's cybersecurity team has activated the incident response plan. Which of the following is the BEST course of action?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate all affected systems from the network immediately to prevent further encryption.
The BEST course of action is to isolate all affected systems (Option B). Containment is the immediate priority in incident response to prevent the ransomware from spreading to uninfected systems. Option A is incorrect because the backups are encrypted and third-party decryption tools are unreliable and may not work. Option C is incorrect if no clean backups exist on removable media; the scenario states backup systems were encrypted. Option D is not recommended as paying the ransom encourages further attacks and does not guarantee data recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restore data from the encrypted backups using a third-party decryption tool.
Why it's wrong here
Encrypted backups are useless without decryption.
- ✓
Isolate all affected systems from the network immediately to prevent further encryption.
Why this is correct
Containment stops the spread and limits damage.
- ✗
Begin restoring systems from any clean backups located on removable media.
Why it's wrong here
Restoration should follow containment and verification that systems are clean.
- ✗
Pay the ransom to obtain the decryption key and restore operations quickly.
Why it's wrong here
Paying is not recommended and may not work.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.