Medium2 marksMultiple Choice

ACCA · Question 11 · Syllabus C: Business functions, regulation and technology

PowerGrid, a public utility company, recently suffered a cyber-attack where malicious software encrypted their critical operational data. The attackers demanded payment in cryptocurrency to provide the decryption key.

Which of the following controls would be the MOST effective in allowing PowerGrid to recover from this specific type of attack without paying the attackers?

Answer options:

A.

Installing advanced antivirus software.

B.

Implementing multi-factor authentication (MFA).

C.

Maintaining isolated, offline data backups.

D.

Encrypting all internal databases.

How to approach this question

Identify the attack as Ransomware. The only way to recover data without paying a ransom is to have a clean, inaccessible copy of the data.

Full Answer

C.Maintaining isolated, offline data backups.✓ Correct
The scenario describes a Ransomware attack. The most effective corrective control for ransomware is having secure, offline backups. Because they are offline, the ransomware cannot spread to them, allowing the company to restore its systems independently.

Common mistakes

Choosing preventive controls (like antivirus or MFA) when the question asks how to *recover* from an attack that has already happened.

Practice the full ACCA BT — Business & Technology Practice Exam 5

52 questions · hints · full answers · grading

More questions from this exam