SY0-701 Security Architecture Practice Question
Exhibit
Backup job summary: - Nightly backups land on a network-attached storage device joined to the domain - Weekly copies are exported to a USB drive and kept in a cabinet in the server room - Backup administrators use the same privileged domain accounts as server admins - No immutable or offline copy exists - Restore tests occur quarterly
Based on the exhibit, which backup protection change best improves ransomware resilience and protects the backup media if it is stolen?
⚠ Common exam trap
Candidates often assume encryption alone (Option A) is sufficient for ransomware protection, overlooking that encryption does not prevent backup corruption or deletion, and that an immutable, air-gapped copy with separate credentials is the only option that addresses both theft and ransomware attack scenarios.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add an immutable offline or air-gapped copy with separate backup credentials and regular restore testing.
Implementing an immutable, offline or air-gapped backup copy with separate credentials ensures that even if an attacker compromises the primary backup system or steals the media, they cannot modify or delete the backups. Regular restore testing verifies the integrity and recoverability of the data, which is critical for ransomware resilience. This approach aligns with the 3-2-1 backup rule and NIST SP 800-184 guidance for cyber recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable backup encryption only, because encrypted backups cannot be read if stolen.
Why it's wrong here
Encryption protects data at rest from unauthorized viewing, but ransomware operates under authenticated user credentials and can encrypt or delete backup files just as easily as production data, regardless of whether they are encrypted. If the encryption keys are stored alongside the backup system, an attacker who compromises that system can access or destroy both keys and data, leaving you with unusable backups. Encryption addresses confidentiality, not integrity or availability, so the backup remains a single point of failure for recovery.
- ✓
Add an immutable offline or air-gapped copy with separate backup credentials and regular restore testing.
Why this is correct
An immutable or offline copy protects backups from tampering, ransomware, and accidental deletion because the attacker cannot easily modify it. Separate credentials reduce the chance that compromised domain admin accounts can reach every backup copy. Regular restore testing ensures the organization can actually recover when needed. This is the strongest improvement in the exhibit.
- ✗
Move the USB drive into a different cabinet inside the same server room.
Why it's wrong here
Moving a USB drive to a different cabinet inside the same server room does not create an air gap because the drive remains connected to the same network and backup infrastructure. Ransomware propagates via network connections and mounted drives, not physical proximity, so a different cabinet offers no additional protection against an attacker who has already compromised the backup system or the domain. Physical separation within the same room also fails to protect against a physical breach, as the attacker could simply access the new cabinet just as easily. This change is purely organizational and does not address the core vulnerability of an online, writable backup.
- ✗
Reduce the retention period so backups consume less storage space.
Why it's wrong here
Reducing the retention period may free up storage space, but it does nothing to protect backups from being encrypted, deleted, or held hostage by ransomware. In fact, shorter retention reduces the number of recovery points, which can cripple your ability to restore to a clean state if the ransomware infection goes undetected for several days or weeks. This approach weakens your recovery point objective (RPO) and recovery time objective (RTO) without eliminating any backup-specific threat vector. The real issue is that the backup is writable and reachable by attackers, not how long you keep it.
Go deeper
Related to this question
Learn chapter
Data Protection and Encryption at Rest
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.