ITPEC FE Subject B October 2024 Question 17

Source exam: ITPEC FE Subject B October 2024Topic: Security Scenarios

ITPEC FE Subject B October 2024 — Question 17 of 20

The scenario describes a ransomware attack on two PCs in an accounting department.

Blank A — Prevention measure:
Point 7: ransomware spread to the shared PC by exploiting OS vulnerabilities because security patches were not applied. The correct prevention measure is OS updates.

  • SPAM filter enhancement is ruled out — point 5 says the phishing email was too sophisticated even for enhanced spam filters
  • Virus definition updates are ruled out — point 8 says anti-virus definitions were already updated daily

Blank B — Data Protection measure:
Point 9: OS storage encryption was already enabled but was not effective against ransomware. Point 4: Employee X's PC had no backup, so data was lost. Point 3: the shared PC had daily backups, so data was restored. The effective data protection measure is data backup.

  • Data encryption is ruled out — point 9 explicitly states encryption was already in place and failed to prevent the attack

Why not others:
- (a) SPAM filter + backup — spam filter part is wrong (point 5 rules it out)

- (b) SPAM filter + encryption — both parts wrong (points 5 and 9)

- (d) OS updates + encryption — encryption already failed (point 9)

- (e) Virus definitions + backup — virus definitions already current (point 8)

- (f) Virus definitions + encryption — both parts wrong (points 8 and 9)

Key rule: When a measure is already in place and proven ineffective in the scenario, it cannot be the correct answer — look for the measure that was missing and would have made a difference.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.