Courseiva
Business Continuity, DR & Incident ResponseeasyMultiple ChoiceObjective-mapped

ISC2 CC Business Continuity, DR & Incident Response Practice Question

You are the cybersecurity lead for a mid-sized retail company. One morning, employees report that they cannot access files on the shared drive, and a ransom note appears on several screens demanding $50,000 in Bitcoin. The company has a formal incident response plan that was last updated two years ago and has never been tested. Backups are taken nightly to an on-premises tape library and also replicated to a cloud storage service but have not been verified recently. The CEO is insisting on paying the ransom to avoid business disruption. Which of the following is the MOST appropriate first course of action?

⚠ Common exam trap

ISC2 often tests the misconception that paying the ransom is the fastest way to recover data, but the correct answer emphasizes containment and verified backups as the primary incident response steps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Isolate the infected systems from the network, then restore data from the most recent verified backup.

The first priority in any ransomware incident is containment: isolating infected systems prevents lateral movement and further encryption. Restoring from the most recent verified backup ensures data integrity and avoids paying the ransom, which does not guarantee decryption and funds criminal activity. The incident response plan should then be activated and updated based on lessons learned.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Delete all infected files and rebuild the file server from scratch without involving backups.

    Why it's wrong here

    Deleting files does not remove the ransomware and would result in permanent data loss if no backups are used.

  • Ignore the incident and continue operations, assuming it will resolve on its own.

    Why it's wrong here

    Ignoring the incident allows the ransomware to spread and cause greater damage.

  • Pay the ransom immediately to minimize downtime and recover data quickly.

    Why it's wrong here

    Paying the ransom is not recommended as it may not lead to data recovery and funds criminal activity.

  • Isolate the infected systems from the network, then restore data from the most recent verified backup.

    Why this is correct

    Isolation stops the spread, and restoring from verified backups is the standard incident response procedure.

About these practice questions

Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.