SY0-701 Security Operations Practice Question
Following a ransomware incident, management wants proof that the organization can actually recover from its backups before declaring the backups trustworthy. What should the security team do next?
⚠ Common exam trap
Many exam-takers confuse backup completion success with backup recoverability, assuming that a successful backup job log is sufficient proof, when in reality only a full restore test in an isolated environment can validate that the data is usable and free from corruption or ransomware payloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restore a backup into an isolated test environment and validate the result.
The only way to prove that backups are trustworthy after a ransomware incident is to perform a full restoration into an isolated test environment and validate the integrity, completeness, and functionality of the recovered data. Simply checking that backup jobs completed successfully (Option A) does not verify that the backup data is uncorrupted, free from ransomware, or restorable in a real scenario. A controlled restore test provides tangible evidence that the recovery process works and the data is usable, which is the core requirement of management’s request for proof of recoverability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check that the backup job completed successfully during the last seven days.
Why it's wrong here
A successful backup job indicates that the backup process ran to completion and data was copied to the backup medium, but it does not verify that the data is intact, complete, or restorable. Backup software can report success even when files are skipped, corrupted, or the backup is unusable due to improper configuration. The seven-day window only demonstrates that backups were attempted, not that they can be recovered during a ransomware incident.
- ✓
Restore a backup into an isolated test environment and validate the result.
Why this is correct
Restoring a backup into an isolated test environment provides direct, empirical proof that the backup data can be successfully recovered and that the restored systems are functional. This validates backup integrity, the restore process, and whether the data meets recovery point and recovery time objectives, all without risking production systems. It is the only way to demonstrate with confidence that the organization can actually recover from the ransomware attack.
- ✗
Increase the backup retention period to reduce the chance of future loss.
Why it's wrong here
Increasing the backup retention period simply keeps more backup copies available for a longer duration, which may help protect against future loss but does nothing to validate that the current backups are restorable. Retention policies address data availability over time, not data recoverability, and they do not test backup integrity or the restoration process. A longer retention period cannot prove that a backup is usable in the event of an incident.
- ✗
Compress the backup files further so they take up less storage.
Why it's wrong here
Compressing backup files further reduces the storage space required, which is a storage optimization technique rather than a recovery validation method. Compression does not improve backup integrity, nor does it confirm that the data can be restored; in fact, additional compression could introduce corruption or increase restore time. The goal of proof in a ransomware incident is to demonstrate recoverability, and compression alone provides no evidence of that.
Go deeper
Related to this question
Learn chapter
Identity and Access Management
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.