FC0-U71 Security Practice Question
Which TWO of the following are effective measures to protect against ransomware attacks? (Select two.)
⚠ Common exam trap
The trap is including options that sound like security measures but actually weaken defenses (disabling firewall, reusing passwords) or are obvious attack vectors (opening unknown attachments), distracting from the two genuine best practices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Installing the latest software updates and patches
Option B is correct because installing the latest software updates and patches closes known vulnerabilities (e.g., SMBv1/EternalBlue, RDP flaws) that ransomware such as WannaCry and NotPetya exploit to gain initial access and propagate laterally. Option D is correct because regularly backing up important files—ideally following the 3-2-1 rule with offline or immutable copies—allows restoration of data without paying a ransom, neutralizing the extortion leverage even if encryption occurs. Option A is wrong because reusing the same password across accounts enables credential-stuffing and lateral movement, dramatically increasing ransomware blast radius rather than protecting against it. Option C is wrong because disabling the firewall removes network traffic filtering and exposes hosts and services to scanning, exploitation, and command-and-control communication. Option E is wrong because opening attachments from unknown senders is a primary ransomware delivery vector via malicious macros, executables, or exploit-laden documents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using the same password for all accounts
Why it's wrong here
Reusing one password across accounts lets a single credential leak unlock everything, and ransomware operators harvest credentials to spread laterally. It is tempting as a memorability shortcut, but password reuse is correct only in scenarios demonstrating poor hygiene, not protection.
- ✓
Installing the latest software updates and patches
Why this is correct
Patching closes the software vulnerabilities that ransomware exploits to gain initial access and propagate. Applying the latest updates directly removes the exposure the stem's attack relies on, making it an effective preventive measure alongside user education and endpoint protection.
- ✗
Disabling the firewall
Why it's wrong here
Disabling the firewall removes filtering of inbound and outbound traffic, letting ransomware payloads and command-and-control connections through unchecked. It is tempting when troubleshooting connectivity, but disabling a firewall would only be defensible temporarily during diagnosis, never as a protective control.
- ✓
Regularly backing up important files
Why this is correct
Maintaining regular backups lets an organisation restore encrypted or deleted files without paying a ransom, directly defeating ransomware's extortion leverage. Offline or immutable copies ensure the backups themselves survive the attack, satisfying the stem's protection requirement.
- ✗
Opening email attachments from unknown senders
Why it's wrong here
Opening attachments from unknown senders executes untrusted payloads, the primary ransomware delivery vector. It is tempting because the attachment may appear to be a legitimate invoice or CV, but opening such files is correct only when demonstrating how infection occurs, not how to prevent it.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.