Medium2 marksMultiple Choice
Syllabus C: Business functions, regulation and technologySection ASyllabus CCyber-securityInternal Controls

ACCA · Question 11 · Syllabus C: Business functions, regulation and technology

A regional hospital network suffers a severe ransomware attack, encrypting patient records and demanding cryptocurrency for the decryption key. Which of the following represents the most effective corrective control the hospital should have in place?

Answer options:

A.

Advanced firewall and intrusion detection systems.

B.

Mandatory cyber-security awareness training for all staff.

C.

Isolated, offline daily data backups.

D.

Biometric access controls to the server room.

How to approach this question

Distinguish between preventative (stopping it), detective (finding it), and corrective (fixing it) controls.

Full Answer

C.Isolated, offline daily data backups.✓ Correct
Controls are categorized by their function. Preventative controls try to stop an event. Detective controls identify it. Corrective controls restore the system to its normal state after an event. Offline backups are the ultimate corrective control for ransomware.

Common mistakes

Choosing firewalls (A) because they are a strong security measure, failing to note the specific request for a *corrective* control.

Practice the full ACCA BT — Business & Technology Practice Exam 1

52 questions · hints · full answers · grading

More questions from this exam