Courseiva
Security ArchitecturemediumMultiple ChoiceObjective-mapped

SY0-701 Security Architecture Practice Question

Exhibit

Backup job summary:
- Nightly backups land on a network-attached storage device joined to the domain
- Weekly copies are exported to a USB drive and kept in a cabinet in the server room
- Backup administrators use the same privileged domain accounts as server admins
- No immutable or offline copy exists
- Restore tests occur quarterly

Based on the exhibit, which backup protection change best improves ransomware resilience and protects the backup media if it is stolen?

⚠ Common exam trap

Candidates often assume encryption alone (Option A) is sufficient for ransomware protection, overlooking that encryption does not prevent backup corruption or deletion, and that an immutable, air-gapped copy with separate credentials is the only option that addresses both theft and ransomware attack scenarios.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Add an immutable offline or air-gapped copy with separate backup credentials and regular restore testing.

Implementing an immutable, offline or air-gapped backup copy with separate credentials ensures that even if an attacker compromises the primary backup system or steals the media, they cannot modify or delete the backups. Regular restore testing verifies the integrity and recoverability of the data, which is critical for ransomware resilience. This approach aligns with the 3-2-1 backup rule and NIST SP 800-184 guidance for cyber recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable backup encryption only, because encrypted backups cannot be read if stolen.

    Why it's wrong here

    Encryption protects data at rest from unauthorized viewing, but ransomware operates under authenticated user credentials and can encrypt or delete backup files just as easily as production data, regardless of whether they are encrypted. If the encryption keys are stored alongside the backup system, an attacker who compromises that system can access or destroy both keys and data, leaving you with unusable backups. Encryption addresses confidentiality, not integrity or availability, so the backup remains a single point of failure for recovery.

  • Add an immutable offline or air-gapped copy with separate backup credentials and regular restore testing.

    Why this is correct

    An immutable or offline copy protects backups from tampering, ransomware, and accidental deletion because the attacker cannot easily modify it. Separate credentials reduce the chance that compromised domain admin accounts can reach every backup copy. Regular restore testing ensures the organization can actually recover when needed. This is the strongest improvement in the exhibit.

  • Move the USB drive into a different cabinet inside the same server room.

    Why it's wrong here

    Moving a USB drive to a different cabinet inside the same server room does not create an air gap because the drive remains connected to the same network and backup infrastructure. Ransomware propagates via network connections and mounted drives, not physical proximity, so a different cabinet offers no additional protection against an attacker who has already compromised the backup system or the domain. Physical separation within the same room also fails to protect against a physical breach, as the attacker could simply access the new cabinet just as easily. This change is purely organizational and does not address the core vulnerability of an online, writable backup.

  • Reduce the retention period so backups consume less storage space.

    Why it's wrong here

    Reducing the retention period may free up storage space, but it does nothing to protect backups from being encrypted, deleted, or held hostage by ransomware. In fact, shorter retention reduces the number of recovery points, which can cripple your ability to restore to a clean state if the ransomware infection goes undetected for several days or weeks. This approach weakens your recovery point objective (RPO) and recovery time objective (RTO) without eliminating any backup-specific threat vector. The real issue is that the backup is writable and reachable by attackers, not how long you keep it.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.