Courseiva

CRISC Information Technology and Security Practice Question

A risk practitioner is reviewing the organization's backup and recovery procedures for critical systems. The organization wants to ensure that backups are protected against ransomware attacks that could encrypt both production data and backups. Which of the following controls is MOST effective for this purpose?

⚠ Common exam trap

The trap here is assuming that encryption or network access controls alone protect backups, when they do not prevent ransomware from encrypting or deleting backup files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing immutable backups that cannot be altered or deleted for a set period.

Immutable backups are the most effective control because they cannot be altered or deleted for a set period, ensuring a clean recovery point even if ransomware compromises the network. Other controls like network access controls, encryption, or backup frequency do not prevent backups from being encrypted or deleted by ransomware.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Performing daily full backups instead of incremental backups.

    Why it's wrong here

    Daily full backups improve recovery point objectives but do not protect against ransomware targeting backups. If the backup storage is accessible, ransomware can encrypt the latest full backup as well. The frequency or type of backup does not address the need for immutability or isolation from the production network.

  • ✗

    Encrypting backups with a strong encryption algorithm.

    Why it's wrong here

    Encryption protects backup data confidentiality but does not prevent ransomware from encrypting or deleting the backup files themselves. If an attacker gains access to the backup storage, they could still encrypt the files, rendering them unusable. Encryption alone does not ensure availability of backups after an attack.

  • ✗

    Storing backups on the same network as production systems with access controls.

    Why it's wrong here

    Storing backups on the same network as production systems increases the risk that ransomware can spread to backups. Even with access controls, if an attacker compromises the network, they may gain access to backup systems. This does not provide adequate isolation, making it less effective against ransomware that targets backups.

  • ✓

    Implementing immutable backups that cannot be altered or deleted for a set period.

    Why this is correct

    Immutable backups prevent modification or deletion, even by administrators or attackers with elevated privileges, for a defined retention period. This ensures that a clean copy of data remains available for recovery after a ransomware attack. It directly addresses the risk of backups being encrypted or destroyed, providing a reliable recovery point.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.