Practice SK0-005 security-disaster-recovery questions with full explanations on every answer.
Start practicing
security-disaster-recovery — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
A server administrator is restoring a file server from a full backup taken 7 days ago and incremental backups taken daily. The restoration fails with an error about missing catalog files. What is the most likely cause?
2A medium-sized company uses a backup strategy that includes a full backup every Sunday at 2:00 AM and differential backups Monday through Saturday at 2:00 AM. The backups are written to a network-attached storage (NAS) device. On Thursday morning, the company experiences a ransomware attack that encrypts all data on the file server, including the NAS. The administrator needs to restore the file server with minimal data loss. The last successful full backup was from the previous Sunday, and differential backups were successful on Monday, Tuesday, and Wednesday. However, Thursday's differential was not completed because the attack occurred before the scheduled time. The administrator attempts to restore using the Sunday full backup and Thursday's differential, but the restore fails because the differential backup on the NAS is also encrypted. Which of the following is the best course of action?
3A small business has a single file server running Windows Server 2019. The server uses two internal SATA drives in a RAID 1 mirror for the operating system and data. The company's backup solution performs a full backup every night to an external USB hard drive, which is stored in the server room. The IT administrator recently noticed that the server's system volume is running low on space and decides to migrate the data to a larger drive. During the migration, the server crashes and will not boot. The administrator attempts to restore from the latest backup but finds that the backup drive is corrupted and cannot be read. The company has no offsite backups. What should the administrator have done to prevent this situation?
4A medium-sized company runs an e-commerce platform on a cluster of three physical servers hosting virtual machines. The disaster recovery plan includes daily backups to a remote data center using Veeam Backup & Replication. The company's annual disaster recovery drill is scheduled for next week. During the drill, the IT team plans to simulate a complete site failure by powering off the primary data center. The recovery time objective (RTO) is 4 hours, and the recovery point objective (RPO) is 1 hour. The team successfully restores the VMs at the remote site, but the application experiences significant performance degradation and many transactions fail due to database inconsistency. Investigation reveals that the backup was taken at 2:00 AM, but the failure occurred at 10:00 AM, and the application's database had transactions between 2:00 AM and 10:00 AM that were not captured. What should the IT team do to improve the recovery process?
5A large enterprise uses a centralized backup solution with a backup server running Commvault. Backups are stored on a deduplicated disk array and replicated to a secondary site for disaster recovery. The company's security team detects ransomware activity that has encrypted several file servers. The backup administrator checks the backup repository and finds that the backup data is also encrypted because the backup service account had permissions to modify backup files, and the ransomware propagated to the repository. The last known good backup is from two weeks ago, which is too old for the organization's RPO of 24 hours. The backup administrator is under pressure to restore operations quickly. Which of the following should the administrator implement to prevent this from recurring?
6A company uses a two-node failover cluster for a critical application. The cluster nodes are located in the same data center, and the quorum configuration uses a file share witness on a separate server in the same data center. During a major power outage, both cluster nodes and the file share witness server lose power. What is the impact on cluster availability?
7A server administrator is responsible for protecting sensitive data. The backup process copies files to a network share daily. Which of the following should the administrator do to BEST ensure the confidentiality of the backup data both during transfer and at rest?
8Refer to the exhibit. An administrator is reviewing logs after a server experienced performance issues and unexpected shutdowns. Based on the log entries, which component is MOST likely failing?
9An organization requires a disaster recovery site that can be operational within 24 hours after a disaster declaration, with critical data replicated on a regular basis, but not necessarily real-time. Which type of site should they implement?
10A company performs a full backup on Sunday and incremental backups Monday through Saturday. A server fails on Thursday at 10:00 AM. Which sequence correctly restores the data?
11A financial services firm requires a disaster recovery site that provides immediate failover with zero data loss. Which type of site should they implement?
12An organization stores backup tapes at an offsite facility. The tapes contain sensitive customer data. A security audit revealed that tapes were stolen from the facility. Which combination of measures would have MOST effectively prevented unauthorized data access?
13Refer to the exhibit. A backup job to a network share failed. The administrator reviews the backup log. What is the most likely cause of the failure?
14Refer to the exhibit. A Linux server's local firewall is configured as shown. The administrator is unable to perform backups to a network-attached storage (NAS) device using TCP port 10000. Which firewall rule is causing the issue?
15A database server hosts a critical application that requires a recovery point objective (RPO) of 4 hours. The company wants to minimize the impact on production performance during backups. Which backup strategy should be implemented?
16A small business has a limited budget and can tolerate up to 72 hours of downtime in the event of a disaster. Which type of disaster recovery site would be most cost-effective?
17After an unexpected power outage, a server fails to boot and displays an error indicating a degraded RAID array. The server has a RAID 5 configuration with four disks. One disk has failed, but the hot spare did not automatically rebuild. The administrator needs to restore data availability as quickly as possible. Which action should the technician take FIRST?
18A system administrator needs to configure secure remote access to servers in the data center. The current setup uses password-based SSH, but the security policy mandates multifactor authentication and prevention of brute-force attacks. Which solution best meets these requirements?
19A company performs annual disaster recovery tests. The last test revealed that the recovery time objective (RTO) was not met because the backup tapes were corrupted. The backup administrator proposes changes to the backup verification process. Which practice is MOST effective to ensure recoverability?
20During a security incident, a server is suspected to be compromised by malware. The incident response team needs to preserve evidence and minimize impact. Which TWO actions should be taken FIRST? (Select TWO.)
21A company is creating a disaster recovery plan for its on-premises data center. Which THREE elements are essential to include in the DR plan? (Select THREE.)
22Refer to the exhibit. A server administrator is reviewing security logs after a suspected brute-force attack on the SSH service. The following excerpt from /var/log/secure is displayed. Which security control would have been MOST effective in preventing the successful login?
23A network administrator needs to configure centralized authentication for network devices. The solution must provide encryption of the entire authentication process, support for multiple protocols, and accounting of user actions. Which protocol should be used?
24A small business needs a disaster recovery site that can be brought online within 2 hours of a primary site failure. The business can tolerate minimal data loss. Which type of recovery site should they implement?
25A system administrator notices unusual file encryption activity on a file server. The activity appears to be rapidly spreading to other servers, and ransom notes are appearing. Which of the following should the administrator do FIRST?
26An organization wants to test its disaster recovery plan with minimal disruption to business operations and minimal cost. The test should verify the plan's effectiveness by discussing scenarios. Which type of test should they perform?
27A financial services firm requires zero data loss in the event of a primary data center failure. They operate two data centers 50 miles apart connected by a high-bandwidth, low-latency link. Which replication method should they use to meet this requirement?
28A mid-sized e-commerce company experienced a ransomware attack that encrypted all on-premises servers and their locally attached backup storage. The attack occurred on a Friday evening; the company was closed over the weekend. By Monday morning, the IT team discovered the encryption and found a ransom note demanding $500,000 in Bitcoin. The company has a disaster recovery plan that calls for restoring from daily tape backups stored offsite. However, the most recent offsite tape was taken home by a backup operator for the weekend and has not been returned. The tape contains full backups from Wednesday. The IT team has clean installation media and application software available. The company's RPO is 24 hours, and RTO is 48 hours. Management wants to minimize data loss and avoid paying the ransom. Based on this scenario, which of the following should the IT team do to recover the business operations?
29A healthcare provider is reviewing its disaster recovery strategy. They have two data centers: one primary in City A and a secondary in City B, 200 miles apart. Currently, they perform daily backups that are replicated to City B each night. In the event of a primary site failure, they can fail over to City B, but there is a 4-hour RTO due to manual processes. Their new RTO target is 2 hours, with an RPO of 15 minutes. The IT team is considering various replication technologies. The provider runs a mix of Windows and Linux servers hosting electronic health records (EHR), PACS imaging, and billing applications. Their current backup scheme is a full backup each night, with transaction logs backed up every 6 hours, but these are not immediately shipped offsite. They have experienced power outages in City A, prompting the review. The IT director is concerned about data consistency and quick recovery. The secondary site currently has sufficient hardware to run all critical applications, but data is only updated nightly. The link between data centers has 100 Mbps bandwidth and 10 ms latency, and upgrading it would cost $50,000. The existing staff can script failover procedures. Which solution best meets the new RPO and RTO while staying within budget?
30A small accounting firm has a single server that hosts their client database and financial applications. The server is backed up nightly using a full backup to an external USB hard drive, which is stored on a shelf next to the server. Last month, a fire broke out in the office, completely destroying the server and the backup drive. The company lost all data since their last offsite backup, which was six months old because they occasionally took a copy home. The business owner wants to prevent such a catastrophic data loss in the future but is concerned about cost and complexity. They have a limited IT budget and no dedicated IT staff. The firm operates 9-5 Monday to Friday, and can tolerate up to 24 hours of downtime and up to one day of data loss. After the fire, they had to rebuild their client records from paper files, which took weeks. The owner realizes the importance of an offsite backup routine but cannot afford an expensive cloud service or a second server. The firm's internet connection is a basic DSL line with limited upload bandwidth, making large cloud backups slow. The server has a single internal drive with enough free space to store additional copies. Which of the following backup strategies would best meet the firm’s recovery objectives while minimizing cost and complexity?
31A regional hospital operates two data centers located 10 miles apart, with synchronous replication of critical patient record systems between them. The replication ensures that any write to the primary storage is immediately mirrored to the secondary site. The hospital also maintains weekly full backups to LTO-8 tapes, which are stored in a fireproof safe at an offsite warehouse 30 miles away. The IT team has not implemented storage snapshots or continuous data protection due to budget constraints. Last week, a ransomware attack encrypted all files on the primary site. The replication process promptly mirrored the encrypted data to the secondary site, rendering both copies inaccessible. The attackers demanded $500,000 in Bitcoin. The hospital's disaster recovery plan specifies an RPO of 1 hour and an RTO of 4 hours. The IT director must now choose a restoration strategy that minimizes data loss and downtime while ensuring a clean, malware-free environment. The backup tapes are confirmed to be unencrypted and free of ransomware. Which of the following actions should the IT director take first?
32A large financial services company must comply with federal regulations mandating quarterly disaster recovery tests. Their primary data center in New York hosts all trading applications, and a hot site in Chicago is maintained with real-time data replication via synchronous mirroring. During the last DR test, the IT team successfully failed over network and storage within 8 minutes, meeting the 15-minute RTO for connectivity. However, they encountered a major issue: the hot site's firewalls, intrusion detection systems, and application-level access controls were not configured to match the primary environment. The security team had to manually create firewall rules, update IDS signatures, and reconfigure access policies based on documentation, which took over 4 hours. As a result, the total system readiness exceeded 4.5 hours, causing a significant gap in trading operations. The regulatory auditor noted this deficiency and required a corrective action plan. The company must ensure that the next DR test achieves full operational readiness, including security controls, within the 15-minute RTO. The IT budget is already allocated for the current fiscal year, so large capital expenditures are not possible, but the team can leverage existing tools and automation. Which of the following is the BEST approach to address this issue?
33A company performs full backups every Sunday and differential backups daily. After a ransomware attack, they discover that both the production data and all attached backup media were encrypted. They need to ensure data can be recovered in the future. Which of the following is the BEST change to their backup strategy?
34An organization's disaster recovery plan specifies an RPO of 4 hours. Their current backup schedule performs a full backup at midnight and incremental backups every 2 hours from 8:00 AM to 8:00 PM. A server failure occurs at 3:00 AM, and data created after 8:00 PM the previous day is permanently lost. Which of the following is the MOST likely reason?
35A financial services firm requires a disaster recovery solution that provides a Recovery Point Objective (RPO) of near zero and a Recovery Time Objective (RTO) of less than 2 hours. Which of the following site types is MOST appropriate?
36An organization uses a cloud-based backup solution with immutable storage to protect against ransomware. However, after a recent attack, an attacker with stolen administrator credentials was able to delete the backup data. Which of the following BEST explains why the backups were deleted?
37Which THREE of the following are typically essential elements of a disaster recovery plan (DRP)? (Choose three.)
38Refer to the exhibit. A disaster recovery test reveals the following timeline for a critical application. The business requires an RTO of 2 hours. Which of the following actions would MOST effectively reduce the RTO to meet the requirement?
39A system administrator configures full backups on Sunday evenings and differential backups on weekdays. On Thursday morning, a disk failure occurs. Which of the following sets of backups is necessary to completely restore the server's data with the fewest number of backup files?
40Refer to the exhibit. A backup administrator scheduled a nightly backup to a network share. The backup job fails with the error shown in the log. What is the most likely cause?
41A medium-sized e-commerce company operates three critical servers: a web front-end, a database server, and a file server. Currently, a full backup of all servers is performed every Sunday starting at 11:00 PM and completes in about 6 hours. Differential backups run each weekday at 11:00 PM, taking roughly 2 hours. On a Wednesday at 10:00 AM, a ransomware attack encrypts all data on all servers. The IT team’s incident response plan requires restoration with an RPO of 4 hours and an RTO of 8 hours. The latest clean backup is Tuesday’s differential, resulting in approximately 10 hours of data loss. Future attacks could occur at any time. Management is willing to spend up to $200 per month to improve the backup strategy but cannot afford new hardware or a dedicated hot site. The team needs a solution that reduces both RPO and RTO within budget while maintaining simplicity for a small IT staff of two. Which of the following backup strategies should be implemented to best meet these requirements?
42A small law firm relies on a single server that hosts a document management system and email. The server is backed up nightly using differential backups to an external USB hard drive that remains connected to the server. One Monday morning, the office manager finds all files encrypted and a ransom note on the screen. The server’s event logs indicate that the encryption began at 2:00 AM on Saturday. The firm’s offsite backup policy rotates two sets of tapes, and the most recent set was taken offsite on Friday evening and is stored in a bank safe deposit box. The USB backup drive, still attached to the server, shows its files also encrypted. The firm does not have a cloud backup service for the server. The office manager wants to restore operations as quickly as possible with minimal data loss and zero risk of reinfection. What is the BEST course of action?
43A small law firm has a single on-premises server running their case management software, email, and document storage. They perform a full backup each night at 11 PM to an external USB 4 TB drive, which is then stored on a shelf in the server room. The server room is located in the basement of their office building. Last week, an electrical fire started in the server room, completely destroying the server and the backup drive. The firm lost all data since the last backup, and it took two weeks to procure new hardware and restore from an older, off-site backup that was taken during a manual process three months ago. Their insurance company now requires a formal disaster recovery plan. The firm has a limited budget and minimal IT staff. They want to prevent data loss and minimize downtime in future disasters. What is the BEST course of action to improve their disaster recovery capabilities?
44A mid-sized manufacturing company operates a primary data center with all critical servers. They have a warm standby site located 100 miles away. For databases, the primary SAN uses synchronous replication to the standby SAN; no tape backups are taken for databases. File and application servers are backed up to an on-premises tape library using nightly incrementals with a weekly full backup every Sunday. Tapes are shipped off-site every Monday morning. On Tuesday morning, a ransomware attack encrypts the entire primary SAN. Because of the real-time replication, the standby SAN is encrypted almost instantly. The on-site tape library is also connected to the network and its tapes, including Sunday's full and Monday's incremental, are encrypted by the attack. The most recent off-site shipment was the previous Monday (eleven days ago), meaning the off-site tapes contain a full backup from eleven days ago and daily incrementals up to that point. The company's RPO is 1 hour for databases and 24 hours for file servers; RTO is 8 hours. The IT director must decide the best immediate course of action to restore operations while adhering to the DR plan as closely as possible.
The security-disaster-recovery domain covers the key concepts tested in this area of the SK0-005 exam blueprint published by CompTIA. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all SK0-005 domains — no account required.
The Courseiva SK0-005 question bank contains 44 questions in the security-disaster-recovery domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the security-disaster-recovery domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included