20+ practice questions focused on security-disaster-recovery — one of the most tested topics on the CompTIA Server+ SK0-005 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start security-disaster-recovery PracticeA server administrator is restoring a file server from a full backup taken 7 days ago and incremental backups taken daily. The restoration fails with an error about missing catalog files. What is the most likely cause?
Explanation: Restoring from incremental backups requires a complete chain from the last full backup. If any incremental backup in the chain is missing or corrupted, the restore will fail. Corrupted full backup media would cause a different error. OS compatibility issues would likely appear earlier. Hard drive failure would be a hardware error.
A medium-sized company uses a backup strategy that includes a full backup every Sunday at 2:00 AM and differential backups Monday through Saturday at 2:00 AM. The backups are written to a network-attached storage (NAS) device. On Thursday morning, the company experiences a ransomware attack that encrypts all data on the file server, including the NAS. The administrator needs to restore the file server with minimal data loss. The last successful full backup was from the previous Sunday, and differential backups were successful on Monday, Tuesday, and Wednesday. However, Thursday's differential was not completed because the attack occurred before the scheduled time. The administrator attempts to restore using the Sunday full backup and Thursday's differential, but the restore fails because the differential backup on the NAS is also encrypted. Which of the following is the best course of action?
Explanation: The most recent clean backup set is Sunday's full plus Wednesday's differential, as both were taken before the ransomware attack. Restoring from these will recover data as of Wednesday's backup, minimizing data loss. Using only Wednesday's differential requires the full backup first. Paying the ransom is not recommended and may not work. Reinstalling the OS and restoring from cloud would not apply because cloud was not mentioned.
A small business has a single file server running Windows Server 2019. The server uses two internal SATA drives in a RAID 1 mirror for the operating system and data. The company's backup solution performs a full backup every night to an external USB hard drive, which is stored in the server room. The IT administrator recently noticed that the server's system volume is running low on space and decides to migrate the data to a larger drive. During the migration, the server crashes and will not boot. The administrator attempts to restore from the latest backup but finds that the backup drive is corrupted and cannot be read. The company has no offsite backups. What should the administrator have done to prevent this situation?
Explanation: The correct answer is D: Regularly test backup restorations to verify data integrity. The administrator assumed backups were valid without verification. Option A is wrong because RAID 1 provides redundancy but does not protect against corruption or accidental deletion; the issue here is backup corruption. Option B is wrong because cloud backup is a good practice but not strictly required; the root cause is lack of backup testing. Option C is wrong because while documentation is helpful, it would not prevent data loss from a corrupted backup drive.
A medium-sized company runs an e-commerce platform on a cluster of three physical servers hosting virtual machines. The disaster recovery plan includes daily backups to a remote data center using Veeam Backup & Replication. The company's annual disaster recovery drill is scheduled for next week. During the drill, the IT team plans to simulate a complete site failure by powering off the primary data center. The recovery time objective (RTO) is 4 hours, and the recovery point objective (RPO) is 1 hour. The team successfully restores the VMs at the remote site, but the application experiences significant performance degradation and many transactions fail due to database inconsistency. Investigation reveals that the backup was taken at 2:00 AM, but the failure occurred at 10:00 AM, and the application's database had transactions between 2:00 AM and 10:00 AM that were not captured. What should the IT team do to improve the recovery process?
Explanation: The correct answer is B: Implement log shipping with point-in-time recovery for the database. The RPO of 1 hour is not being met because the backup schedule is daily. Option A is wrong because while a faster WAN can reduce backup time, the core issue is the backup frequency, not bandwidth. Option C is wrong because the issue is not data redundancy but recovery granularity; RAID protects against drive failure but not data loss from missing transactions. Option D is wrong because increasing RTO does not solve the RPO violation; the goal is to reduce data loss, not relax the time target.
A large enterprise uses a centralized backup solution with a backup server running Commvault. Backups are stored on a deduplicated disk array and replicated to a secondary site for disaster recovery. The company's security team detects ransomware activity that has encrypted several file servers. The backup administrator checks the backup repository and finds that the backup data is also encrypted because the backup service account had permissions to modify backup files, and the ransomware propagated to the repository. The last known good backup is from two weeks ago, which is too old for the organization's RPO of 24 hours. The backup administrator is under pressure to restore operations quickly. Which of the following should the administrator implement to prevent this from recurring?
Explanation: The correct answer is A: Implement immutable backup storage and use a separate service account with write permissions only during backup windows. Immutable backups cannot be modified or deleted by any user or process, including ransomware. Option B is wrong because air-gapping alone does not prevent access if the backup server is compromised; immutable storage is more robust. Option C is wrong because while MFA is a good security practice, it does not protect backups that are already accessible with valid credentials. Option D is wrong because encryption of backup data protects it during transit or while stored, but does not prevent the ransomware from encrypting the files if the backup system is accessible.
+15 more security-disaster-recovery questions available
Practice all security-disaster-recovery questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of security-disaster-recovery. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
security-disaster-recovery questions on the SK0-005 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. security-disaster-recovery is tested as part of the CompTIA Server+ SK0-005 blueprint. Practicing with targeted security-disaster-recovery questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SK0-005 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but security-disaster-recovery is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full security-disaster-recovery practice session with instant scoring and detailed explanations.
Start security-disaster-recovery Practice →