Certified Information Security Manager (CISM) — Question 925
A new type of ransomware has infected an organization's network. Which of the following would have BEST enabled the organization to detect this situation?
Answer options
- A. Periodic information security training for end users
- B. Use of integrated patch deployment tools
- C. Regular review of the threat landscape
- D. Monitoring of anomalies in system behavior
Correct answer: D
Explanation
Monitoring of anomalies in system behavior is crucial for detecting unusual activities that may indicate a ransomware infection. While training, patch deployment, and threat landscape reviews are important, they do not provide real-time detection capabilities like monitoring system behavior does.