Courseiva
Question 109 of 144
security-disaster-recoverymediumScenarioObjective-mapped

SK0-005 security-disaster-recovery Practice Question

A regional hospital operates two data centers located 10 miles apart, with synchronous replication of critical patient record systems between them. The replication ensures that any write to the primary storage is immediately mirrored to the secondary site. The hospital also maintains weekly full backups to LTO-8 tapes, which are stored in a fireproof safe at an offsite warehouse 30 miles away. The IT team has not implemented storage snapshots or continuous data protection due to budget constraints. Last week, a ransomware attack encrypted all files on the primary site. The replication process promptly mirrored the encrypted data to the secondary site, rendering both copies inaccessible. The attackers demanded $500,000 in Bitcoin. The hospital's disaster recovery plan specifies an RPO of 1 hour and an RTO of 4 hours. The IT director must now choose a restoration strategy that minimizes data loss and downtime while ensuring a clean, malware-free environment. The backup tapes are confirmed to be unencrypted and free of ransomware. Which of the following actions should the IT director take first?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Wipe the secondary data center storage, restore from the latest clean tape backup at the secondary site, and then reverse replication to the primary.

Option C is correct because both the primary and secondary copies are encrypted, so the only clean data source is the offsite tape. Wiping the secondary site, restoring from tape there, and then reversing replication to the primary ensures a malware-free environment and uses the existing replication infrastructure to bring the primary back online quickly, potentially within the 4-hour RTO. Option A is unrealistic since no decryption tool is available for modern ransomware without the key. Option B runs the risk of the primary becoming reinfected if any remnants remain, and it leaves the encrypted secondary uncorrected. Option D is inadvisable as paying the ransom does not guarantee data recovery and funds criminal activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Pay the ransom demand to obtain the decryption key and decrypt both sites.

    Why it's wrong here

    Paying ransoms encourages further attacks, provides no guarantee the key will work, and violates many regulatory and ethical standards for healthcare organizations.

  • Restore the most recent tape backup to the primary site and re-enable replication.

    Why it's wrong here

    Restoring directly to the primary without first wiping the secondary could lead to re-encryption if the ransomware is not fully eradicated, and replication would propagate the encrypted data again.

  • Fail over to the secondary data center and attempt to decrypt the ransomware using available tools.

    Why it's wrong here

    Modern ransomware typically uses strong encryption that cannot be broken without the key; publicly available tools rarely succeed, so this approach almost certainly fails to restore data.

  • Wipe the secondary data center storage, restore from the latest clean tape backup at the secondary site, and then reverse replication to the primary.

    Why this is correct

    This method isolates the recovery to a known-clean environment, uses the tape copy (only reliable clean source), and leverages existing replication to efficiently restore the primary with minimal downtime.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jul 26, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SK0-005 exam.