A ransomware alert shows encrypted file shares and a ransom note on a critical file server. The incident manager asks whether to begin payment negotiations. What should the SOC analyst verify first?
Select an answer to reveal the explanation.
Short Explanation
Think of ransomware response like trying to rebuild a house: you check whether the blueprints and bricks still work before paying someone to hand them back. You need to know if your backups are clean and restorable before payment enters the conversation. The trap is treating negotiation as the fastest path when recovery feasibility is the first decision gate.
Full Explanation
In a ransomware incident, the first recovery question is whether the organization can restore from unaffected, trustworthy backups. Confirm backup integrity, isolation from the compromised network, recency, and actual restorability to compatible systems. If a clean, tested backup can meet recovery objectives, payment negotiation is unnecessary and may introduce legal, reputational, and financing risk. If backups cannot be restored, leadership must make a structured risk decision, not an ad hoc payment choice. Data exfiltration matters because it may indicate a reportable breach and can strengthen extortion pressure, but it does not tell you whether restoration is feasible. Antivirus signature currency and detection coverage help assess initial detection, scope, and containment confidence, yet they do not prove backup quality; an updated agent can coexist with corrupted backups. Valid cryptocurrency addresses and payment logistics are administrative details, not a security recovery criterion; they also require legal, sanctions, insurance, and executive approval. Exam caveat: choose recovery feasibility before negotiation when ransomware response asks for the first verification step. Operational check: restore a representative backup into an isolated sandbox, verify hashes or signatures, confirm application functionality, and document RPO/RTO attainment.