SY0-701 Security Operations Practice Question
Exhibit
Disaster recovery review for the customer billing platform Current backup design: - Full backup once per day at 23:00 - Backups stored on the same storage cluster as production VM snapshots - Backup administrator account is shared by the operations team - Restore test cadence: none in the last 12 months - Current measured restore time from bare metal: 7 hours Business recovery targets: - RTO: 2 hours - RPO: 15 minutes
Based on the exhibit, which improvement best aligns the current backup design with the stated recovery targets?
⚠ Common exam trap
CompTIA often tests the misconception that simply extending retention or making backups faster (e.g., removing encryption) improves recovery, when in reality the key gaps are off-site immutability and restore testing to ensure recoverability against ransomware and operational errors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Switch to frequent incremental or snapshot backups stored in a separate, immutable location with routine restore tests.
The current backup design lacks off-site, immutable storage and routine restore testing, which are critical to meet recovery point and time objectives (RPO/RTO). Frequent incremental or snapshot backups in a separate, immutable location protect against ransomware and ensure data integrity, while routine restore tests verify that backups are actually recoverable when needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Keep the same design but extend backup retention from 30 days to 90 days.
Why it's wrong here
Extending the retention period from 30 to 90 days addresses archival or compliance requirements, but it does nothing to narrow the recovery point objective (RPO) or speed up the recovery time objective (RTO). The root problem is that backups run infrequently—if the last full backup is 24 hours old, you lose up to 24 hours of data no matter how long you keep it. Longer retention also increases storage and management overhead without improving restore performance or resilience against ransomware.
- ✓
Switch to frequent incremental or snapshot backups stored in a separate, immutable location with routine restore tests.
Why this is correct
The business needs a much smaller RPO and a faster RTO than the current design can deliver. More frequent backups reduce the amount of data lost, while a separate immutable repository improves resilience against ransomware and storage failures. Regular restore tests confirm that the chosen method actually meets the recovery objective in practice, not just on paper.
- ✗
Share the backup administrator password in a team chat so any engineer can restore data during an outage.
Why it's wrong here
Sharing the backup administrator password in team chat violates the principle of least privilege and destroys non-repudiation, because every restore or modification would lose a clear audit trail. It does not improve recovery time or recovery point, and it increases the risk of accidental or malicious changes by expanding the attack surface beyond authorized personnel. A shared password also complicates background checks, revocation, and breach attribution.
- ✗
Remove backup encryption so restores run faster during an emergency.
Why it's wrong here
Removing backup encryption would expose production data in transit and at rest, violating confidentiality requirements and potentially failing compliance mandates such as HIPAA or PCI DSS. Modern hardware typically offloads encryption, so decryption overhead is rarely the bottleneck in a restore—network throughput and disk speed are far more limiting. Eliminating encryption does not make backups more frequent, immutable, or isolated, so the original RTO/RPO and ransomware-resilience problems remain unsolved.
Go deeper
Related to this question
Learn chapter
Container Hardening Best Practices
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.