Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A company's file server was infected with ransomware, and all files were encrypted. The IT team has daily backups stored on a separate network-attached storage (NAS) appliance. However, the backups were also encrypted because the backup service account had full write permissions to the NAS share. The backup account was a domain administrator account. Which of the following should the organization implement to BEST prevent this scenario from recurring?

⚠ Common exam trap

The trap here is that candidates often focus on account privilege reduction (Option B) as the best practice, but fail to recognize that ransomware can still encrypt backups if the backup service account has any write access, because the encryption process modifies existing files; immutable storage is the only option that makes modification impossible by design.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use immutable backup storage that enforces write-once, read-many (WORM) policies

Immutable backup storage with WORM policies ensures that once data is written, it cannot be modified or deleted by any account, including domain administrators. This directly prevents ransomware from encrypting backups because the ransomware process, even running with elevated privileges, cannot alter the immutable snapshots. This is the most effective solution because it eliminates the attack vector at the storage layer, regardless of account permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use immutable backup storage that enforces write-once, read-many (WORM) policies

    Why this is correct

    Immutable backup storage with write-once, read-many (WORM) policies is the definitive defense because it renders backups logically tamper-proof for a defined retention window. Even if ransomware escalates to full administrative rights or compromises the backup service account, it cannot overwrite, encrypt, or delete the stored snapshots or objects. This guarantees a clean recovery point that survives the attack, which is the fundamental requirement for restoring operations after a ransomware incident.

  • ✗

    Create a separate backup service account with limited privileges and disable interactive logon

    Why it's wrong here

    While least privilege is important, a backup account still needs write access to the backup location. If ransomware compromises that account, it could still encrypt backups. This alone does not fully prevent the recovery scenario.

  • ✗

    Require multifactor authentication for access to the backup repository

    Why it's wrong here

    MFA adds a layer of security for authentication, but if the ransomware runs with the backup service account's token, it may not need to reauthenticate. MFA does not protect against modification of data using already-stolen credentials.

  • ✗

    Encrypt backup data at rest using BitLocker or similar technology

    Why it's wrong here

    Encrypting backup data at rest with BitLocker or similar technology protects confidentiality if media is stolen, but it does nothing to preserve integrity or availability during an active ransomware attack. Ransomware running with appropriate privileges can simply re-encrypt already-encrypted data (or encrypt the unencrypted file system that BitLocker transparently decrypts at the OS layer), thereby still making the backups unrecoverable. Encryption is a security control for data privacy, not a resilience control, and it cannot prevent the malicious modification or deletion that ransomware performs.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.