Question 40 of 144
SK0-005 security-disaster-recovery Practice Question
A small law firm relies on a single server that hosts a document management system and email. The server is backed up nightly using differential backups to an external USB hard drive that remains connected to the server. One Monday morning, the office manager finds all files encrypted and a ransom note on the screen. The server’s event logs indicate that the encryption began at 2:00 AM on Saturday. The firm’s offsite backup policy rotates two sets of tapes, and the most recent set was taken offsite on Friday evening and is stored in a bank safe deposit box. The USB backup drive, still attached to the server, shows its files also encrypted. The firm does not have a cloud backup service for the server. The office manager wants to restore operations as quickly as possible with minimal data loss and zero risk of reinfection. What is the BEST course of action?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reimage the server, then restore data from the Friday offsite tape backup.
A is correct. The offsite tape backup from Friday evening is air-gapped and predates the infection (Saturday 2:00 AM), ensuring it is clean. Reimaging the server provides a known-good operating system. Option B is risky because the USB drive’s backup likely contains infected files; even an antivirus scan might not detect all ransomware artifacts. Option C is not possible since there is no server cloud backup. Option D is not recommended and may not result in file recovery. Thus, A is the safest and most reliable method.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restore the server from the firm's cloud backup service for email.
Why it's wrong here
There is no cloud backup for the server; the scenario states the firm has no such service.
- ✗
Scan the USB drive with antivirus, then restore the latest differential backup from it.
Why it's wrong here
The USB drive was connected during the encryption and is likely compromised; antivirus may not fully clean it, and the backup itself may contain encrypted or infected files.
- ✗
Pay the ransom to obtain the decryption key, then perform a full backup.
Why it's wrong here
Paying the ransom does not guarantee file recovery, encourages criminal activity, and may not result in a fully clean system.
- ✓
Reimage the server, then restore data from the Friday offsite tape backup.
Why this is correct
Offsite tape is clean and the reimage ensures no malware persists, providing a fresh, reliable start.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jul 26, 2026
This SK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SK0-005 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.