What is the FIRST action an incident responder should take upon discovering an active ransomware infection on a corporate workstation?
-
A
Pay the ransom to recover files quickly
-
B
Isolate the infected system from the network immediately
-
C
Reimage the system from a clean backup
-
D
Contact law enforcement before doing anything else