After ransomware hits the library, IT restores systems from backups and rebuilds servers. Which control type best describes those restoration actions?
Select an answer to reveal the explanation.
Short Explanation
Restoring from backup is the cybersecurity version of replacing a broken window after the storm — you are fixing the damage, not stopping the hail mid-air. That fix-it-afterward role is corrective. Hardening and patching beforehand would have been preventive.
Full Explanation
Corrective controls remediate or restore after an adverse event to reduce impact and return systems toward a known-good state. Restoring from backups and rebuilding compromised servers are corrective actions. Preventive controls aim to stop the incident from succeeding; detective controls discover it; directive controls mandate required behavior through policy. Maintaining backups may support resilience planning, but the act of restoration after ransomware is classified as corrective.