mediumMultiple Choice
220-1202 Practice Question: A security incident is reported where a user…
A security incident is reported where a user accidentally deleted a critical script in /usr/local/bin. The script was owned by root and had permissions 755. Which command will restore the script from a backup located in /backup?
⚠ Common exam trap
Test-takers frequently choose `cp` without `-p` (Option B) because they assume a simple copy is sufficient, overlooking that file ownership and permissions are not preserved by default. A second trap is choosing `cp -p` (Option C) assuming it always preserves root ownership, when in fact a non-root user cannot set ownership to root; `rsync -a` is the reliable restoration command.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
rsync -a /backup/script.sh /usr/local/bin/
The `rsync -a` command uses archive mode, which preserves ownership, permissions, timestamps, and other attributes when restoring the script from /backup to /usr/local/bin. Since the script was owned by root and had permissions 755, `-a` ensures these attributes are retained, which is critical for a system script in /usr/local/bin. A plain `cp` (Option B) would not preserve ownership or permissions, and `cp -p` (Option C) only preserves attributes when the user has sufficient privilege to set them; it is not the standard tool for restoring a root-owned file. `mv` (Option A) simply moves the backup file and does not restore it while preserving the original attributes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
mv /backup/script.sh /usr/local/bin/
Why it's wrong here
mv moves the file but does not preserve permissions by default; the backup may have different permissions.
- ✗
cp /backup/script.sh /usr/local/bin/
Why it's wrong here
This copies the file but does not preserve the original permissions; it will use the backup's permissions.
- ✗
cp -p /backup/script.sh /usr/local/bin/
Why it's wrong here
The -p flag preserves the original file's permissions, timestamps, and ownership if run as root.
- ✓
rsync -a /backup/script.sh /usr/local/bin/
Why this is correct
rsync -a preserves attributes but is overkill for a single file; it would work but is not the simplest command.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.