hardMultiple ChoiceObjective-mapped
CS0-003 Practice Question: After containing a ransomware outbreak, the…
After containing a ransomware outbreak, the incident response team needs to restore encrypted files. They have verified clean backups from two weeks ago, but some critical files were modified on the day of the attack. What is the best approach?
⚠ Common exam trap
CompTIA often tests the misconception that restoring from the most recent clean backup is always sufficient, ignoring the need to preserve post-backup legitimate changes, which leads candidates to choose Option D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restore critical files from backup and manually update them using change logs
Restoring critical files from backup and manually updating them using change logs preserves the modifications made on the day of the attack, which are not present in the two-week-old backups. This approach ensures data integrity by combining the clean baseline from backups with the legitimate changes recorded in change logs, avoiding data loss while maintaining security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restore from backups and then apply all available updates
Why it's wrong here
This approach would restore systems to a pre-ransomware state, potentially from an older backup, and then secure them against known vulnerabilities by applying updates. However, it fails to recover any legitimate data modifications or new files created between the last successful backup and the ransomware incident. Applying updates prevents future exploitation but does not magically restore lost or encrypted data from the period immediately preceding the attack, resulting in significant data loss for recent work.
- ✓
Restore critical files from backup and manually update them using change logs
Why this is correct
This is the most effective strategy as it leverages clean, uninfected backups for the bulk of the data, ensuring system integrity and a secure foundation. For critical files that experienced legitimate modifications between the last backup and the incident, change logs, transaction logs, or user-reported changes can be used to manually re-apply those specific updates. This meticulous process minimizes data loss by reconciling recent legitimate changes with the restored clean baseline, providing the highest level of data integrity and business continuity post-incident.
- ✗
Attempt to decrypt files using the ransom key
Why it's wrong here
Attempting to decrypt files using a key obtained by paying the ransom is strongly discouraged by cybersecurity best practices and law enforcement agencies. There is no guarantee that the attackers will provide a working decryption key, or any key at all, even after payment. Furthermore, paying ransom incentivizes future attacks and funds criminal enterprises, making it an unsustainable and unethical recovery strategy that does not guarantee data restoration.
- ✗
Restore all files from backups
Why it's wrong here
Restoring all files indiscriminately from backups, while ensuring a clean system, would result in the complete loss of all legitimate data changes, new files, and system configurations made since the last backup was taken. If the last backup is several days or weeks old, this could mean significant operational disruption and irretrievable loss of critical business data and productivity. This approach prioritizes speed over data integrity, which is often unacceptable for modern business operations.
Go deeper
Related to this question
Learn chapter
Endpoint Detection and Response
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.