Question 83 of 144
SK0-005 security-disaster-recovery Practice Question
A large enterprise uses a centralized backup solution with a backup server running Commvault. Backups are stored on a deduplicated disk array and replicated to a secondary site for disaster recovery. The company's security team detects ransomware activity that has encrypted several file servers. The backup administrator checks the backup repository and finds that the backup data is also encrypted because the backup service account had permissions to modify backup files, and the ransomware propagated to the repository. The last known good backup is from two weeks ago, which is too old for the organization's RPO of 24 hours. The backup administrator is under pressure to restore operations quickly. Which of the following should the administrator implement to prevent this from recurring?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Immutable backup storage and a dedicated service account with least-privilege access.
The correct answer is A: Implement immutable backup storage and use a separate service account with write permissions only during backup windows. Immutable backups cannot be modified or deleted by any user or process, including ransomware. Option B is wrong because air-gapping alone does not prevent access if the backup server is compromised; immutable storage is more robust. Option C is wrong because while MFA is a good security practice, it does not protect backups that are already accessible with valid credentials. Option D is wrong because encryption of backup data protects it during transit or while stored, but does not prevent the ransomware from encrypting the files if the backup system is accessible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Immutable backup storage and a dedicated service account with least-privilege access.
Why this is correct
Immutable storage ensures backups cannot be altered or deleted, and a least-privilege service account reduces the attack surface. This prevents ransomware from encrypting or destroying backups.
- ✗
Encrypt all backup data at rest and in transit.
Why it's wrong here
Encryption protects confidentiality but does not prevent destruction or modification of the backup data. Ransomware can encrypt already-encrypted files, making them unrecoverable.
- ✗
Require multi-factor authentication for the backup service account.
Why it's wrong here
MFA adds security but if the ransomware gains access through the account (e.g., via a compromised client), it can still encrypt backups. Immutable storage is needed.
- ✗
Air-gap the backup repository by disconnecting it from the network except during backup windows.
Why it's wrong here
Air-gapping helps but is not foolproof; if the backup server is compromised during the window, ransomware can still spread. Immutability is a stronger safeguard.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jul 26, 2026
This SK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SK0-005 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.