mediummultiple choiceObjective-mapped

A branch office uses a NAS for nightly backups, but the NAS is joined to the same domain as the production servers. After ransomware encrypted both production data and backups, management wants the most effective change to reduce the chance of backup tampering without a major redesign. Which control should be implemented?

Question 1mediummultiple choice
Full question →

A branch office uses a NAS for nightly backups, but the NAS is joined to the same domain as the production servers. After ransomware encrypted both production data and backups, management wants the most effective change to reduce the chance of backup tampering without a major redesign. Which control should be implemented?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Run backups more frequently to the same NAS so newer files are captured sooner.

More frequent backups do not help if the same ransomware can still encrypt or delete the backup repository.

B

Distractor review

Increase the retention period so deleted files can be recovered for longer.

Longer retention helps with recovery options, but it does not stop the attacker from tampering with active backups.

C

Distractor review

Move backups to a larger NAS with more available storage capacity.

Additional storage alone does not improve resilience if the backup system remains equally reachable and writable.

D

Best answer

Keep one backup copy offline or immutable and outside the production domain.

An offline or immutable copy is the strongest practical protection against ransomware that can reach the network backup target. Separating that copy from the production domain also reduces the chance that compromised admin credentials can alter it. This improves resilience without requiring a full redesign, and it gives the organization a trusted recovery source even if online backups are encrypted or deleted.

Common exam trap

Common exam trap: answer the scenario, not the keyword

Many certification questions include familiar terms but test a specific constraint. Read the exact wording before choosing an answer that is generally true but wrong for this case.

Technical deep dive

How to think about this question

This question should be treated as a scenario, not a definition check. Identify the problem, the constraint and the best action. Then compare each option against those facts.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.
  • Use explanations to understand the rule behind the answer.

TExam Day Tips

  • Underline the problem statement mentally.
  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Related practice questions

Related SY0-701 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this SY0-701 question test?

Read the scenario before looking for a memorised answer.

What is the correct answer to this question?

The correct answer is: Keep one backup copy offline or immutable and outside the production domain. — The most effective improvement is to keep at least one backup copy offline or immutable and separate from the production domain. That breaks the attacker’s ability to use compromised credentials or malware to encrypt, delete, or alter the recovery set. This approach directly addresses backup tampering while preserving recovery options. It is one of the most reliable resilience controls for ransomware scenarios. Why others are wrong: A helps with retention but not tamper resistance. B provides capacity, not security. D improves recovery point only if the backups survive, which they may not on a domain-joined NAS. The main risk here is that backups are too accessible, not that they are too infrequent.

What should I do if I get this SY0-701 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.