Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A systems administrator says the backup software reports success every night, but no one has restored a server from backup in over a year. The business wants confidence that a file server can be recovered within the agreed recovery window. What is the best next action?

⚠ Common exam trap

A common mix-up: candidates assume backup success logs are sufficient proof of recoverability, but CompTIA emphasizes that only a documented restore test can verify the backup's usability and adherence to the RTO.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perform a scheduled restore test in an isolated environment and measure the recovery time.

The only way to validate that backups are both restorable and meet the recovery time objective (RTO) is to perform a scheduled restore test in an isolated environment. Backup success logs only confirm that data was copied, not that the data is intact or that the restoration process completes within the agreed window. This aligns with the 3-2-1 backup rule and the principle of 'trust but verify' in backup validation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Trust the success status because completed jobs prove the backups are usable.

    Why it's wrong here

    A backup job that reports "success" only indicates that the software wrote data to the storage target without detecting an immediate error. It does not validate that the data is bit-for-bit intact, that the backup catalog is readable, or that the application can actually restore the files. Corruption, incomplete file lists, and media faults frequently surface only when a restore is attempted, so trusting the success status alone is unverified confidence.

  • Perform a scheduled restore test in an isolated environment and measure the recovery time.

    Why this is correct

    Performing a scheduled restore test in an isolated environment directly validates that the backup media contains usable data and that the restore procedure works end-to-end. This practice confirms the organization can meet its recovery point objective (RPO) and recovery time objective (RTO) by measuring how long the restore actually takes. It also surfaces hidden issues such as missing dependencies or permission problems while avoiding production disruption.

  • Delete older backups so that only the most recent set remains.

    Why it's wrong here

    Deleting older backups collapses the available recovery points, meaning that if the most recent backup is corrupted, incomplete, or rendered unusable by ransomware, the organization may lose far more data than necessary. It also eliminates the ability to restore to a point-in-time before a silent data corruption or infection occurred. Pruning retention reduces recovery options and does nothing to prove the current backup is actually restorable.

  • Extend retention indefinitely to avoid ever losing a recoverable copy.

    Why it's wrong here

    Extending retention indefinitely raises storage and management costs without adding any validation that a restore will succeed. Older backups may still be corrupt, and simply holding more copies does not improve confidence in the restore process or the underlying data integrity. Furthermore, indefinite retention can violate data governance policies or legal requirements, creating compliance risk while failing to address the core need for recoverability.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.