Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

After a ransomware event, the team restores a file server from backup, but management wants proof that the restore process will work before the backups are declared trusted. What should be done next?

⚠ Common exam trap

Watch out — candidates often think simply having backups is sufficient proof of recoverability, but the exam emphasizes that only a successful test restore in an isolated environment can validate the backup's integrity and the restore process itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perform a test restore in an isolated environment and verify the recovered data

The only way to prove that backups are trustworthy is to perform a test restore in an isolated environment, verifying the integrity and completeness of the recovered data. This validates that the backup process, media, and software are functioning correctly without risking the production environment. Without a successful test restore, the team cannot confirm that the backups are free from corruption, encryption, or other issues that would prevent a real recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Delete the old backup copies to prevent future confusion

    Why it's wrong here

    Deleting old backup copies after a ransomware event eliminates recovery points and may also destroy digital evidence needed for forensic investigation or legal proceedings. While older backups might contain the malware or be dated, confusion is better addressed through a defined retention policy and clear labeling, not by removing data. The only way to prove reliability is a test restore, so deleting backups does not validate the recovery process and increases the risk of permanent data loss.

  • Perform a test restore in an isolated environment and verify the recovered data

    Why this is correct

    A test restore is the best way to validate backup integrity and operational readiness after an incident. Restoring in isolation confirms that the backup can be used successfully without risking production systems. Verification should include checking file integrity, application access if relevant, and whether the restored data meets recovery objectives. This provides evidence that backups remain trustworthy after ransomware.

  • Switch to incremental backups only so the next restore is faster

    Why it's wrong here

    Switching to incremental backups immediately after an incident does nothing to confirm that the current full or synthetic backup can actually be restored, which is the immediate priority. Incremental-only strategies create a dependency chain where every daily difference file must be intact, so a single corrupted or missing incremental can render the entire restore unusable. Instead, you should validate the existing backup media through a test restore and then adjust the backup schedule based on measured recovery time objectives (RTO) and recovery point objectives (RPO), not on an assumption that faster backups equal safer recovery.

  • Store the backups on the same file server so they are easier to access

    Why it's wrong here

    Storing backup copies on the same file server as production data violates the 3-2-1 backup rule and exposes those copies to the same ransomware attack vector, since the server's file permissions or credentials may be compromised. If the attacker gains access, they can encrypt or delete both the original files and the backups in one operation, leaving no recovery option. Additionally, local backups are accessible from the server itself, so a successful remote code execution or stored XSS could result in total data loss. Offsite or immutable offline backups are necessary to ensure a safe recovery point.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.