The Chief Information Security Officer (CISO) is concerned about business application availability. The organization was recently subject to a ransomware attack that resulted in the unavailability of applications and services for 10 working days that required paper-based running of all main business processes. There are now aggressive plans to enhance the Recovery Time Objective (RTO) and cater for more frequent data captures.
Which of the following solutions should be implemented to fully comply to the new business requirements?
Correct Answer: A
Virtualization is a solution that can help to enhance the recovery time objective (RTO) and cater for more frequent data captures, as required by the new business requirements. Virtualization is a technique that creates a virtual version of a resource, such as a server, a storage, a network, or an application, that can run on a physical platform. Virtualization can improve the availability, scalability, and performance of the resources, as well as reduce the cost, complexity, and risk of the resources. Virtualization can help to achieve a shorter RTO, which is the maximum acceptable time to restore the normal operations and services after a disruption or disaster. Virtualization can enable faster recovery of the resources, by using techniques such as snapshots, backups, replication, or failover. Virtualization can also help to cater for more frequent data captures, which can reduce the data loss and improve the data integrity. Virtualization can enable more frequent data captures, by using techniques such as incremental backups, differential backups, or continuous data protection.
Antivirus, process isolation, and host-based intrusion prevention system (HIPS) are not solutions that can help to enhance the RTO and cater for more frequent data captures, as required by the new business requirements.
Antivirus is a software tool that detects and removes malicious software, such as viruses, worms, trojans, or ransomware, from a system or a network. Antivirus can help to protect the confidentiality, integrity, and availability of the data and the system, but it does not directly affect the RTO or the data capture frequency.
Process isolation is a security technique that separates the processes running on a system or a network, so that they do not interfere with each other or access each other's resources. Process isolation can help to prevent the propagation, escalation, or exploitation of the processes, but it does not directly affect the RTO or the data capture frequency. Host-based intrusion prevention system (HIPS) is a security tool that monitors and blocks malicious or anomalous activities on a host, such as a server, workstation, or device. HIPS can help to protect the host from attacks, such as malware, exploits, or unauthorized changes, but it does not directly affect the RTO or the data capture frequency. References: Official (ISC)2 CISSP CBK Reference, Fifth Edition, Domain 3, Security Architecture and Engineering, page 293. CISSP All-in-One Exam Guide, Eighth Edition, Chapter 3, Security Architecture and Engineering, page 256.