Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

Following a ransomware incident, management wants to verify that backups are usable and that a restored file server will meet recovery expectations before declaring the system trusted again. Which action is best?

⚠ Common exam trap

Many candidates assume backup logs or increased retention are sufficient to prove recoverability, but CompTIA emphasizes that only a documented restore test in an isolated environment provides the empirical evidence needed to declare a system trusted after a security incident.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perform a documented restore test in an isolated environment and validate the recovered data.

Performing a documented restore test in an isolated environment is the only action that directly validates the integrity and usability of backups, ensuring the restored file server meets recovery point objective (RPO) and recovery time objective (RTO) expectations. This process verifies that the backup data is not corrupted, encrypted, or incomplete, which is critical after a ransomware incident where backups may have been targeted. Without such a test, management cannot confidently declare the system trusted, as logs or retention changes do not prove data recoverability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Review the backup job logs and mark the backups as valid.

    Why it's wrong here

    Reviewing backup job logs only confirms that the backup process executed without error, not that the resulting data is intact, restorable, or free from ransomware encryption. Attackers frequently disable or compromise backup agents so that logs report success while the underlying data is corrupted. Logs cannot simulate a recovery; they provide no evidence about the usability of the restored files, so marking the backups valid based solely on logs is insufficient.

  • Perform a documented restore test in an isolated environment and validate the recovered data.

    Why this is correct

    A documented restore test in an isolated environment is the definitive verification because it actually exercises the recovery process from the backup media to a fully functional state, proving the data can be recovered and used. Isolating the environment prevents any latent ransomware from spreading into the production network, while validating the recovered data ensures files are uncorrupted and services meet continuity requirements. This aligns with the 3-2-1 rule's recovery objective and provides the evidence management needs.

  • Increase the retention period so more restore points are available later.

    Why it's wrong here

    Increasing the retention period only extends how long existing restore points are kept, it does nothing to prove that any current backup can actually be restored or that it contains clean data. If a backup was already encrypted by ransomware or suffered silent corruption, retaining it longer simply preserves an unusable artifact. Retention-based changes are proactive for future incidents; they do not satisfy the immediate need to validate post-incident recoverability.

  • Create a new full backup immediately after the incident and trust that one instead.

    Why it's wrong here

    Creating a new full backup immediately after the incident is premature because the new backup may include dormant malware, partially encrypted files, or incomplete data if the system is not fully cleaned first. Even if the backup completes successfully, it has not been tested, so there is no assurance it can be restored to a working state during a disaster. Trusting a fresh backup without a restore validation repeats the exact risk the incident exposed, leaving the organization without verified recovery capability.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.