SY0-701 Security Operations Practice Question
A technician restores a file server from backup, but the business wants confidence that the recovery process will work during an outage. What should the team do most often to validate the backups?
⚠ Common exam trap
Many exam-takers assume that simply having backups or extending retention is sufficient, but CompTIA emphasizes that only actual restore testing provides verifiable proof of recoverability, not the presence of backup files or vendor claims.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform regular restore tests using sample files or systems.
The only way to gain confidence that backups can be successfully restored during an actual outage is to perform regular, documented restore tests. This validates the integrity of the backup media, the correctness of the restoration procedure, and the recoverability of data within the required recovery time objective (RTO). Without testing, assumptions about backup reliability remain unverified, which can lead to catastrophic data loss when a real disaster occurs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Review the backup vendor brochure for proof that recovery will work.
Why it's wrong here
A vendor brochure describes the intended features and capabilities of the backup solution, but it provides zero evidence about the actual state of your backups, storage media, or recovery environment. It cannot verify that your specific data was written correctly, that the media is readable, or that the restore process will work under your infrastructure. Marketing material is not a substitute for empirical validation of the restoration path.
- ✓
Perform regular restore tests using sample files or systems.
Why this is correct
Performing regular restore tests entails recovering sample files or an entire system from backup to a scratch or isolated environment to prove the data is readable and complete. This process validates not only the backup media but also the backup software's ability to reassemble files, directories, and application state correctly. It directly verifies achievement of recovery point and recovery time objectives, giving confidence that a real disaster can be recovered.
- ✗
Increase the backup retention period without testing restores.
Why it's wrong here
Increasing backup retention periods simply means you keep more historical restore points, but it does nothing to confirm that any of those points are restorable. If the backup job produced a corrupt index, the storage media has degraded, or the data was written with errors, retaining it longer only preserves the problem. Without restore verification, a longer retention window can create a false sense of security and delay the discovery of an unusable backup chain.
- ✗
Change the backup password every day and skip verification.
Why it's wrong here
Changing the backup password daily strengthens access control and helps encrypt credentials, but it is irrelevant to the integrity or restorability of the backup content. Skipping verification means you never actually read the data back from the media, so you could be unaware of bit rot, truncation, or software defects that render the backup useless. Credential management and recovery validation are separate controls; the former protects the data, the latter proves the data can be recovered.
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Recovery time objective
Recovery time objective (RTO) is the maximum acceptable time that an IT system can be offline after a failure before the business is severely impacted.
Key term
RTO
Recovery Time Objective is the maximum acceptable time to restore a system or data after a disaster, defining how quickly normal operations must resume.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.