mediummultiple choiceObjective-mapped

An engineering firm backs up its file server every night to a NAS that is always mounted to the production domain. After a ransomware event, management asks for the most effective improvement to reduce the chance that backups are encrypted along with production data. What should be recommended?

Question 1mediummultiple choice
Full question →

An engineering firm backs up its file server every night to a NAS that is always mounted to the production domain. After a ransomware event, management asks for the most effective improvement to reduce the chance that backups are encrypted along with production data. What should be recommended?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Increase the backup frequency but leave the NAS always online

More frequent backups help recovery points, but they do not protect backups from being attacked while online.

B

Best answer

Keep an offline or immutable backup copy that is not continuously reachable from production

Offline or immutable backups resist encryption by ransomware because the attacker cannot easily modify or destroy them from the compromised environment.

C

Distractor review

Store backups in the same server room for faster restore times

Physical proximity may improve convenience, but it does not reduce the risk that ransomware reaches the backup data.

D

Distractor review

Use only local snapshots on the file server because they are simpler to manage

Local snapshots are useful, but they can still be deleted or encrypted if the attacker gains sufficient access.

Common exam trap

Common exam trap: answer the scenario, not the keyword

Many certification questions include familiar terms but test a specific constraint. Read the exact wording before choosing an answer that is generally true but wrong for this case.

Technical deep dive

How to think about this question

This question should be treated as a scenario, not a definition check. Identify the problem, the constraint and the best action. Then compare each option against those facts.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.
  • Use explanations to understand the rule behind the answer.

TExam Day Tips

  • Underline the problem statement mentally.
  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Related practice questions

Related SY0-701 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this SY0-701 question test?

Read the scenario before looking for a memorised answer.

What is the correct answer to this question?

The correct answer is: Keep an offline or immutable backup copy that is not continuously reachable from production — The best resilience improvement is to keep an offline or immutable backup copy that is not always reachable from production systems. Ransomware often looks for mounted shares, backup repositories, and management credentials to destroy recovery options. By removing continuous access or making the data immutable, the organization greatly improves the chance of successful restoration after an incident. This is a core operational control for backup protection. Why others are wrong: A improves recovery point but not backup survivability. C focuses on convenience rather than resilience and can make a single physical event more damaging. D may help with short-term rollback, but snapshots are not a substitute for protected backups. The key issue is separating recovery data from the same trust boundary as production systems.

What should I do if I get this SY0-701 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.