SY0-701 Security Operations Practice Question
After a ransomware event, the team restores a file server from backup, but management wants proof that the restore process will work before the backups are declared trusted. What should be done next?
⚠ Common exam trap
Watch out — candidates often think simply having backups is sufficient proof of recoverability, but the exam emphasizes that only a successful test restore in an isolated environment can validate the backup's integrity and the restore process itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a test restore in an isolated environment and verify the recovered data
The only way to prove that backups are trustworthy is to perform a test restore in an isolated environment, verifying the integrity and completeness of the recovered data. This validates that the backup process, media, and software are functioning correctly without risking the production environment. Without a successful test restore, the team cannot confirm that the backups are free from corruption, encryption, or other issues that would prevent a real recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the old backup copies to prevent future confusion
Why it's wrong here
Deleting old backup copies after a ransomware event eliminates recovery points and may also destroy digital evidence needed for forensic investigation or legal proceedings. While older backups might contain the malware or be dated, confusion is better addressed through a defined retention policy and clear labeling, not by removing data. The only way to prove reliability is a test restore, so deleting backups does not validate the recovery process and increases the risk of permanent data loss.
- ✓
Perform a test restore in an isolated environment and verify the recovered data
Why this is correct
A test restore is the best way to validate backup integrity and operational readiness after an incident. Restoring in isolation confirms that the backup can be used successfully without risking production systems. Verification should include checking file integrity, application access if relevant, and whether the restored data meets recovery objectives. This provides evidence that backups remain trustworthy after ransomware.
- ✗
Switch to incremental backups only so the next restore is faster
Why it's wrong here
Switching to incremental backups immediately after an incident does nothing to confirm that the current full or synthetic backup can actually be restored, which is the immediate priority. Incremental-only strategies create a dependency chain where every daily difference file must be intact, so a single corrupted or missing incremental can render the entire restore unusable. Instead, you should validate the existing backup media through a test restore and then adjust the backup schedule based on measured recovery time objectives (RTO) and recovery point objectives (RPO), not on an assumption that faster backups equal safer recovery.
- ✗
Store the backups on the same file server so they are easier to access
Why it's wrong here
Storing backup copies on the same file server as production data violates the 3-2-1 backup rule and exposes those copies to the same ransomware attack vector, since the server's file permissions or credentials may be compromised. If the attacker gains access, they can encrypt or delete both the original files and the backups in one operation, leaving no recovery option. Additionally, local backups are accessible from the server itself, so a successful remote code execution or stored XSS could result in total data loss. Offsite or immutable offline backups are necessary to ensure a safe recovery point.
Go deeper
Related to this question
Learn chapter
Identity and Access Management
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.