mediumMultiple Choice
CISM Practice Question: A company experiences ransomware that encrypts…
A company experiences ransomware that encrypts critical servers. Backups are available but were taken 2 weeks ago. What is the best course?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restore from backups after verifying no residual malware and performing security scans
Restore from backups after verifying no residual malware and performing security scans to ensure clean restoration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restore from backups immediately
Why it's wrong here
Restoring immediately reinstates two-week-old data and may reintroduce the still-present threat actor or undetected persistence, so containment and forensic scoping must precede recovery. It is tempting because backups are the standard ransomware recovery path, and would be correct once the environment is confirmed clean and the acceptable data-loss window is validated.
- ✓
Restore from backups after verifying no residual malware and performing security scans
Why this is correct
Restoring from two-week-old backups is the only viable recovery path, but integrity demands verifying the restored data and scanning for residual malware or persistence mechanisms before reconnecting to production, satisfying the stem's need to resume operations without reintroducing the ransomware.
- ✗
Rebuild servers from scratch
Why it's wrong here
Rebuilding from scratch discards recoverable data and is unnecessary when viable backups exist, and it does not by itself remove the initial access vector. It is tempting because clean rebuilds guarantee no residual malware, and would be correct if backups were also compromised or the infection's scope could not be determined.
- ✗
Pay the ransom
Why it's wrong here
Paying the ransom funds criminals without guaranteeing decryption and may violate sanctions or regulatory obligations. It is tempting as a fast route to restored access when backups are stale, but restoring the two-week-old backups and accepting limited data loss is the defensible recovery path.
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.