Courseiva
General Security ConceptsmediumMultiple ChoiceObjective-mapped

SY0-701 General Security Concepts Practice Question

A security analyst is investigating a data integrity incident where an attacker exploited a vulnerability in a web application to alter customer account balance records in the database. The analyst identifies the exact records that were modified and restores those records from a verified read-only backup taken prior to the attack. Which security goal is the analyst primarily addressing by restoring the records from backup?

⚠ Common exam trap

A common mix-up: candidates confuse restoring data from backup with ensuring availability, but the primary goal in this scenario is to correct unauthorized modifications, which is a core integrity function.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Integrity

Restoring the altered customer account balance records from a verified read-only backup directly addresses the integrity security goal. Integrity ensures that data is accurate and has not been modified by unauthorized parties. By reverting the records to their pre-attack state, the analyst is correcting the unauthorized modifications, thereby restoring the trustworthiness of the data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Confidentiality

    Why it's wrong here

    Confidentiality protects data from unauthorized disclosure and is enforced through access controls, encryption, and data classification. The incident described focuses on unauthorized modification, not unauthorized viewing or exfiltration, so the primary violation is integrity rather than confidentiality. Even though restoring the backup might remove any malicious modifications, it does not address whether an attacker read or copied sensitive data during the incident, nor does it mitigate the exposure. Thus, confidentiality is an important but separate concern that this restoration action does not directly resolve.

    When this WOULD be correct

    A security analyst discovers that an attacker exfiltrated sensitive customer data from a database. The analyst restores the database from a backup to ensure that any backdoors or unauthorized copies are removed, but the primary goal addressed is preventing further unauthorized access, i.e., confidentiality.

  • Integrity

    Why this is correct

    Integrity is the security goal that assures data remains accurate, complete, and unchanged from its legitimate state. In this scenario, the unauthorized modifications directly violate that requirement, because the database no longer reflects the original authorized values. Restoring from a known-good backup is a corrective control that re-establishes an untampered baseline, thereby remediating the integrity breach and returning the data to a trustworthy condition.

  • Availability

    Why it's wrong here

    Availability ensures systems and data are accessible when needed. While the restoration does make the correct data available again, the primary driver for the action is to fix the integrity violation, not to restore availability (which was not lost).

    When this WOULD be correct

    A question where a DDoS attack overwhelms a web server, making customer accounts inaccessible, and the analyst restores service from a backup to ensure uptime. The primary goal addressed would be availability.

  • Non-repudiation

    Why it's wrong here

    Non-repudiation is the assurance that a party cannot deny a specific action, such as creating or modifying a record, and is typically implemented through digital signatures or cryptographic audit trails. Restoring a database from backup does not preserve or generate evidence about who made the unauthorized changes; it merely rolls the data back to an earlier point in time. As a result, while backup restoration can help recover from an integrity incident, it does not provide non-repudiation because it lacks tamper-proof proof of the original action.

    When this WOULD be correct

    Non-repudiation would be correct if the question asked about ensuring that a user cannot deny performing a transaction, such as by implementing digital signatures or audit logs that provide proof of origin and integrity.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

IntegrityCorrect answer

Why this is correct

Integrity is the security goal that assures data remains accurate, complete, and unchanged from its legitimate state. In this scenario, the unauthorized modifications directly violate that requirement, because the database no longer reflects the original authorized values. Restoring from a known-good backup is a corrective control that re-establishes an untampered baseline, thereby remediating the integrity breach and returning the data to a trustworthy condition.

ConfidentialityWrong answer — click to see why

Why this is wrong here

Restoring records from a backup directly addresses the alteration of data, which is an integrity issue, not confidentiality. Confidentiality concerns unauthorized disclosure, not unauthorized modification.

★ When this WOULD be the correct answer

A security analyst discovers that an attacker exfiltrated sensitive customer data from a database. The analyst restores the database from a backup to ensure that any backdoors or unauthorized copies are removed, but the primary goal addressed is preventing further unauthorized access, i.e., confidentiality.

Why candidates choose this

Candidates may confuse data protection with data integrity, thinking that restoring from backup protects data from being seen, but the key is that the incident involved modification, not disclosure.

AvailabilityWrong answer — click to see why

Why this is wrong here

Restoring records from backup addresses data integrity by correcting unauthorized modifications, not availability, which concerns ensuring systems and data are accessible when needed.

★ When this WOULD be the correct answer

A question where a DDoS attack overwhelms a web server, making customer accounts inaccessible, and the analyst restores service from a backup to ensure uptime. The primary goal addressed would be availability.

Why candidates choose this

Candidates may confuse restoring from backup with ensuring system uptime, mistakenly thinking that any backup restoration primarily supports availability rather than correcting data corruption.

Non-repudiationWrong answer — click to see why

Why this is wrong here

Restoring records from backup addresses integrity by reverting unauthorized modifications, not non-repudiation, which concerns proving actions occurred (e.g., digital signatures).

★ When this WOULD be the correct answer

Non-repudiation would be correct if the question asked about ensuring that a user cannot deny performing a transaction, such as by implementing digital signatures or audit logs that provide proof of origin and integrity.

Why candidates choose this

Candidates may confuse integrity (data correctness) with non-repudiation (accountability), thinking that restoring from backup provides proof of original data, but non-repudiation focuses on attribution of actions, not data restoration.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.