Courseiva
Security OperationsmediumMultiple SelectObjective-mapped

How to Validate Backups Meet Recovery Time Objectives

Management wants to ensure a file server backed up every night can actually be restored within a 4-hour recovery time objective after an incident. Which two actions best improve recovery confidence? Select two.

Quick Answer

The answer is to perform scheduled restore tests to an isolated environment and keep at least one backup copy offline or immutable. These two actions directly improve recovery confidence because scheduled restore tests validate that backup data is both readable and usable without risking production corruption, while an offline or immutable copy ensures a clean, tamper-proof fallback if the primary backup is compromised by ransomware or human error. On the Security+ SY0-701 exam, this scenario tests your understanding of recovery validation and the 3-2-1 backup rule, often appearing as a multi-select question where distractors include “incremental backups” or “cloud replication” without testing restore speed. A common trap is assuming that simply having backups guarantees RTO compliance; the exam emphasizes that only actual restore testing measures real-world timing. Memory tip: “Test and isolate—don’t just replicate.”

⚠ Common exam trap

Many candidates confuse backup retention (how long backups are kept) with backup recoverability, assuming that longer retention inherently improves recovery confidence, when in fact only periodic restore testing proves that backups are viable and can meet the RTO.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perform scheduled restore tests to an isolated environment.

Performing scheduled restore tests to an isolated environment validates that the backup data is both readable and usable without risking corruption of the production environment. This directly confirms the ability to meet the 4-hour RTO by measuring actual restore times and identifying any issues with the backup process or media before a real incident occurs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Perform scheduled restore tests to an isolated environment.

    Why this is correct

    Correct because restore testing proves the backups are usable and helps measure actual recovery time. A backup that has never been restored cannot be assumed to meet the recovery objective.

  • Keep at least one backup copy offline or immutable.

    Why this is correct

    Correct because offline or immutable copies protect against ransomware and tampering. That increases the odds that a known-good recovery point will still exist when the organization needs it.

  • Increase retention to keep backups for two years without changing restore testing.

    Why it's wrong here

    Incorrect because longer retention alone does not prove recoverability. Old backups that are never tested may still fail when restoration is needed.

  • Move the backup repository onto the same always-mounted file share as production data.

    Why it's wrong here

    Placing the backup repository on the same always-mounted file share as production data eliminates offline isolation, meaning a ransomware attack or storage failure that corrupts the live share simultaneously destroys the backup set. This directly violates the requirement for a restorable copy within the 4-hour RTO, because no independent recovery source exists. It is tempting because co-location simplifies storage management and reduces network transfer time, and would be correct in a scenario where the RTO is zero and continuous data protection from the live volume is acceptable.

  • Reduce the number of user permissions on the file server without changing backup design.

    Why it's wrong here

    Incorrect because access reduction may be good hygiene, but it does not directly improve recovery confidence. The question asks about restore assurance and resilience.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A technician restores a file server from backup, but the business wants confidence that the recovery process will work during an outage. What should the team do most often to validate the backups?

easy
  • A.Review the backup vendor brochure for proof that recovery will work.
  • B.Perform regular restore tests using sample files or systems.
  • C.Increase the backup retention period without testing restores.
  • D.Change the backup password every day and skip verification.

Why B: The only way to gain confidence that backups can be successfully restored during an actual outage is to perform regular, documented restore tests. This validates the integrity of the backup media, the correctness of the restoration procedure, and the recoverability of data within the required recovery time objective (RTO). Without testing, assumptions about backup reliability remain unverified, which can lead to catastrophic data loss when a real disaster occurs.

Variation 2. Based on the exhibit, what should the team do next to confirm the backups can actually be used during an outage?

easy
  • A.Increase the retention period before making any restore attempts.
  • B.Perform a test restore to a nonproduction location and verify the recovered files.
  • C.Delete older backup sets so the backup window is shorter.
  • D.Convert the backups to full backups only so the status report is simpler.

Why B: The only way to confirm that backups are usable during an outage is to perform a test restore to a nonproduction location and verify the recovered files. This validates the integrity of the backup data, the restore process, and that the files are complete and functional, which is a core principle of backup validation (often called a 'restore test' or 'disaster recovery drill'). Simply reviewing backup status reports or increasing retention does not prove that the data can be successfully restored.

Variation 3. A virtual file server was restored from last night’s backup. The service is online, but some finance users report missing spreadsheet changes and a few files show a 'recovered copy' timestamp. Which two checks should be completed before the team accepts the restore as successful? Select two.

hard
  • A.Compare restored data against backup hashes or a manifest to verify that the copy is complete and uncorrupted.
  • B.Run an application-level validation test with finance users or sample transactions to confirm the data is usable.
  • C.Assume the restore is acceptable because the file server is online and users can browse shares.
  • D.Delete the previous night’s backup so the team will not accidentally restore it again.
  • E.Expose the restored server directly to the internet so remote users can test it faster.

Why A: Comparing restored data against backup hashes or a manifest ensures the data integrity and completeness of the restore process. Even though the file server is online, missing spreadsheet changes and 'recovered copy' timestamps suggest possible corruption or incomplete restoration. Verifying hashes (e.g., SHA-256) against a known-good manifest confirms that every file was restored without bit-rot or truncation, which is a standard post-restore validation step in backup and recovery procedures.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.