SY0-701 General Security Concepts Practice Question
A security analyst is investigating a data integrity incident where an attacker exploited a vulnerability in a web application to alter customer account balance records in the database. The analyst identifies the exact records that were modified and restores those records from a verified read-only backup taken prior to the attack. Which security goal is the analyst primarily addressing by restoring the records from backup?
⚠ Common exam trap
A common mix-up: candidates confuse restoring data from backup with ensuring availability, but the primary goal in this scenario is to correct unauthorized modifications, which is a core integrity function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrity
Restoring the altered customer account balance records from a verified read-only backup directly addresses the integrity security goal. Integrity ensures that data is accurate and has not been modified by unauthorized parties. By reverting the records to their pre-attack state, the analyst is correcting the unauthorized modifications, thereby restoring the trustworthiness of the data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Confidentiality
Why it's wrong here
Confidentiality protects data from unauthorized disclosure and is enforced through access controls, encryption, and data classification. The incident described focuses on unauthorized modification, not unauthorized viewing or exfiltration, so the primary violation is integrity rather than confidentiality. Even though restoring the backup might remove any malicious modifications, it does not address whether an attacker read or copied sensitive data during the incident, nor does it mitigate the exposure. Thus, confidentiality is an important but separate concern that this restoration action does not directly resolve.
When this WOULD be correct
A security analyst discovers that an attacker exfiltrated sensitive customer data from a database. The analyst restores the database from a backup to ensure that any backdoors or unauthorized copies are removed, but the primary goal addressed is preventing further unauthorized access, i.e., confidentiality.
- ✓
Integrity
Why this is correct
Integrity is the security goal that assures data remains accurate, complete, and unchanged from its legitimate state. In this scenario, the unauthorized modifications directly violate that requirement, because the database no longer reflects the original authorized values. Restoring from a known-good backup is a corrective control that re-establishes an untampered baseline, thereby remediating the integrity breach and returning the data to a trustworthy condition.
- ✗
Availability
Why it's wrong here
Availability ensures systems and data are accessible when needed. While the restoration does make the correct data available again, the primary driver for the action is to fix the integrity violation, not to restore availability (which was not lost).
When this WOULD be correct
A question where a DDoS attack overwhelms a web server, making customer accounts inaccessible, and the analyst restores service from a backup to ensure uptime. The primary goal addressed would be availability.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation is the assurance that a party cannot deny a specific action, such as creating or modifying a record, and is typically implemented through digital signatures or cryptographic audit trails. Restoring a database from backup does not preserve or generate evidence about who made the unauthorized changes; it merely rolls the data back to an earlier point in time. As a result, while backup restoration can help recover from an integrity incident, it does not provide non-repudiation because it lacks tamper-proof proof of the original action.
When this WOULD be correct
Non-repudiation would be correct if the question asked about ensuring that a user cannot deny performing a transaction, such as by implementing digital signatures or audit logs that provide proof of origin and integrity.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓IntegrityCorrect answer▾
Why this is correct
Integrity is the security goal that assures data remains accurate, complete, and unchanged from its legitimate state. In this scenario, the unauthorized modifications directly violate that requirement, because the database no longer reflects the original authorized values. Restoring from a known-good backup is a corrective control that re-establishes an untampered baseline, thereby remediating the integrity breach and returning the data to a trustworthy condition.
✗ConfidentialityWrong answer — click to see why▾
Why this is wrong here
Restoring records from a backup directly addresses the alteration of data, which is an integrity issue, not confidentiality. Confidentiality concerns unauthorized disclosure, not unauthorized modification.
★ When this WOULD be the correct answer
A security analyst discovers that an attacker exfiltrated sensitive customer data from a database. The analyst restores the database from a backup to ensure that any backdoors or unauthorized copies are removed, but the primary goal addressed is preventing further unauthorized access, i.e., confidentiality.
Why candidates choose this
Candidates may confuse data protection with data integrity, thinking that restoring from backup protects data from being seen, but the key is that the incident involved modification, not disclosure.
✗AvailabilityWrong answer — click to see why▾
Why this is wrong here
Restoring records from backup addresses data integrity by correcting unauthorized modifications, not availability, which concerns ensuring systems and data are accessible when needed.
★ When this WOULD be the correct answer
A question where a DDoS attack overwhelms a web server, making customer accounts inaccessible, and the analyst restores service from a backup to ensure uptime. The primary goal addressed would be availability.
Why candidates choose this
Candidates may confuse restoring from backup with ensuring system uptime, mistakenly thinking that any backup restoration primarily supports availability rather than correcting data corruption.
✗Non-repudiationWrong answer — click to see why▾
Why this is wrong here
Restoring records from backup addresses integrity by reverting unauthorized modifications, not non-repudiation, which concerns proving actions occurred (e.g., digital signatures).
★ When this WOULD be the correct answer
Non-repudiation would be correct if the question asked about ensuring that a user cannot deny performing a transaction, such as by implementing digital signatures or audit logs that provide proof of origin and integrity.
Why candidates choose this
Candidates may confuse integrity (data correctness) with non-repudiation (accountability), thinking that restoring from backup provides proof of original data, but non-repudiation focuses on attribution of actions, not data restoration.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Security Controls
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.