会社の最高情報セキュリティ責任者は、会社がランサムウェアの標的になることを防ぎたいと考えています。会社の IT 資産を保護する必要があります。これらの懸念に対処するための最も安全なオプションは次のどれですか? (3 つ選択してください)。
正解:B,C,D
To prevent ransomware attacks and protect IT assets, the most secure options are:
* Endpoint Detection and Response (EDR): Provides advanced threat detection, real-time monitoring, and response capabilities, which can help identify and mitigate ransomware attacks before they spread.
* Sandboxing: Isolates suspicious files or software in a controlled environment where they can be analyzed for malicious behavior without affecting production systems.
* Application Control: Ensures that only whitelisted, trusted applications can run, which can prevent ransomware from executing unauthorized or malicious code.Together, these controls provide a robust defense against ransomware by addressing detection, isolation, and prevention. CASP+ emphasizes the importance of combining detection and prevention strategies to mitigate sophisticated attacks like ransomware.
References:
* CASP+ CAS-004 Exam Objectives: Domain 2.0 - Enterprise Security Operations (Endpoint Protection, Ransomware Mitigation)
* CompTIA CASP+ Study Guide: Mitigating Ransomware with EDR, Sandboxing, and Application Control