easyMultiple ChoiceObjective-mapped
CS0-003 Practice Question: A small business with 50 employees uses a single…
A small business with 50 employees uses a single Windows Server 2019 as a domain controller and file server. The company recently experienced a ransomware attack that encrypted all files on the server. The IT manager restored the files from a backup that was taken two days before the attack. However, the next day, the files were encrypted again. The analyst suspects the ransomware may have persisted or re-entered. The network is air-gapped from the internet, but employees use USB drives. Which of the following is the MOST likely reason for the re-infection?
⚠ Common exam trap
Many exam-takers assume the backup was infected (Option A) or that patching (Option D) is the root cause, but the air-gap and USB vector point directly to physical media reintroduction, not network-based persistence or patch status.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An employee inserted an infected USB drive after the restoration.
The network is air-gapped from the internet, leaving USB drives as the primary vector for reintroducing malware. If an employee inserted an infected USB drive after the restoration, the ransomware could execute and re-encrypt the files. The air-gap eliminates internet-based re-entry, and the backup was clean since it restored files without immediate re-encryption until the next day.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The backup itself contained the ransomware.
Why it's wrong here
This option is incorrect because a fundamental principle of disaster recovery is to restore from a known good state, typically a backup created before the initial compromise. If the backup itself contained the ransomware, it would mean the organization was infected much earlier than realized, or the backup integrity was compromised, making the restoration effort futile from the start. Assuming a properly isolated and verified backup was used, this scenario is highly improbable for a re-infection event occurring immediately after restoration.
- ✓
An employee inserted an infected USB drive after the restoration.
Why this is correct
This is the most plausible explanation for a re-infection following a successful restoration from a clean backup. After a system is restored, it often operates in a vulnerable state, potentially with reduced network connectivity or security controls temporarily relaxed for validation. An employee inserting an infected USB drive directly into the server or a connected workstation provides a direct, physical vector for malware re-introduction, bypassing network perimeter defenses that might have been re-established. This action re-establishes the infection chain.
- ✗
The ransomware was still active in memory on the server.
Why it's wrong here
This option is incorrect because a system restoration, particularly from a bare-metal backup or a full system image, inherently involves a complete shutdown and reboot of the server. This process clears all volatile memory (RAM), effectively eradicating any active ransomware processes or malicious code residing solely in memory. Therefore, ransomware cannot persist in memory across a system restoration and subsequent reboot, making re-infection from memory impossible.
- ✗
The domain controller was not fully patched.
Why it's wrong here
While maintaining a fully patched domain controller is critical for overall security, a lack of patches primarily exposes the system to exploits targeting known software vulnerabilities. This would not directly cause a re-infection via an infected USB drive, which is a vector relying on user action or auto-run features, not necessarily an unpatched vulnerability on the server itself. Patching prevents exploitation of software flaws, but not the introduction of malware through physical media or social engineering.
Go deeper
Related to this question
Learn chapter
Network Traffic Analysis
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.