ISC2 CC Business Continuity, DR & Incident Response Practice Question
You are the cybersecurity lead for a mid-sized retail company. One morning, employees report that they cannot access files on the shared drive, and a ransom note appears on several screens demanding $50,000 in Bitcoin. The company has a formal incident response plan that was last updated two years ago and has never been tested. Backups are taken nightly to an on-premises tape library and also replicated to a cloud storage service but have not been verified recently. The CEO is insisting on paying the ransom to avoid business disruption. Which of the following is the MOST appropriate first course of action?
⚠ Common exam trap
ISC2 often tests the misconception that paying the ransom is the fastest way to recover data, but the correct answer emphasizes containment and verified backups as the primary incident response steps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the infected systems from the network, then restore data from the most recent verified backup.
The first priority in any ransomware incident is containment: isolating infected systems prevents lateral movement and further encryption. Restoring from the most recent verified backup ensures data integrity and avoids paying the ransom, which does not guarantee decryption and funds criminal activity. The incident response plan should then be activated and updated based on lessons learned.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete all infected files and rebuild the file server from scratch without involving backups.
Why it's wrong here
Deleting files does not remove the ransomware and would result in permanent data loss if no backups are used.
- ✗
Ignore the incident and continue operations, assuming it will resolve on its own.
Why it's wrong here
Ignoring the incident allows the ransomware to spread and cause greater damage.
- ✗
Pay the ransom immediately to minimize downtime and recover data quickly.
Why it's wrong here
Paying the ransom is not recommended as it may not lead to data recovery and funds criminal activity.
- ✓
Isolate the infected systems from the network, then restore data from the most recent verified backup.
Why this is correct
Isolation stops the spread, and restoring from verified backups is the standard incident response procedure.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Lessons learned
Lessons learned is the process of capturing, analyzing, and documenting knowledge gained from past incidents or projects to improve future security operations and prevent recurrence of problems.
About these practice questions
Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.