220-1102 Security Practice Question
A company's file server was infected with ransomware, and all files were encrypted. The IT team has daily backups stored on a separate network-attached storage (NAS) appliance. However, the backups were also encrypted because the backup service account had full write permissions to the NAS share. The backup account was a domain administrator account. Which of the following should the organization implement to BEST prevent this scenario from recurring?
⚠ Common exam trap
The trap here is that candidates often focus on account privilege reduction (Option B) as the best practice, but fail to recognize that ransomware can still encrypt backups if the backup service account has any write access, because the encryption process modifies existing files; immutable storage is the only option that makes modification impossible by design.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use immutable backup storage that enforces write-once, read-many (WORM) policies
Immutable backup storage with WORM policies ensures that once data is written, it cannot be modified or deleted by any account, including domain administrators. This directly prevents ransomware from encrypting backups because the ransomware process, even running with elevated privileges, cannot alter the immutable snapshots. This is the most effective solution because it eliminates the attack vector at the storage layer, regardless of account permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use immutable backup storage that enforces write-once, read-many (WORM) policies
Why this is correct
Immutable backup storage with write-once, read-many (WORM) policies is the definitive defense because it renders backups logically tamper-proof for a defined retention window. Even if ransomware escalates to full administrative rights or compromises the backup service account, it cannot overwrite, encrypt, or delete the stored snapshots or objects. This guarantees a clean recovery point that survives the attack, which is the fundamental requirement for restoring operations after a ransomware incident.
- ✗
Create a separate backup service account with limited privileges and disable interactive logon
Why it's wrong here
While least privilege is important, a backup account still needs write access to the backup location. If ransomware compromises that account, it could still encrypt backups. This alone does not fully prevent the recovery scenario.
- ✗
Require multifactor authentication for access to the backup repository
Why it's wrong here
MFA adds a layer of security for authentication, but if the ransomware runs with the backup service account's token, it may not need to reauthenticate. MFA does not protect against modification of data using already-stolen credentials.
- ✗
Encrypt backup data at rest using BitLocker or similar technology
Why it's wrong here
Encrypting backup data at rest with BitLocker or similar technology protects confidentiality if media is stolen, but it does nothing to preserve integrity or availability during an active ransomware attack. Ransomware running with appropriate privileges can simply re-encrypt already-encrypted data (or encrypt the unencrypted file system that BitLocker transparently decrypts at the OS layer), thereby still making the backups unrecoverable. Encryption is a security control for data privacy, not a resilience control, and it cannot prevent the malicious modification or deletion that ransomware performs.
Go deeper
Related to this question
Learn chapter
Data Sanitization: Wipe, Degauss, Shred, Incinerate
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.