mediumMultiple Choice
ISC2 CC Practice Question: A company experiences a ransomware attack that…
A company experiences a ransomware attack that encrypts all files on a server. Which security control would MOST effectively allow recovery without paying the ransom?
⚠ Common exam trap
The trap is assuming antivirus or firewall 'prevents' ransomware well enough to avoid the need for recovery; the exam wants the control that enables restoration, which is backups.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regular backups
Regular backups are the most effective control for recovering from ransomware because they allow restoration of data to a known-good state without paying the ransom. Ransomware encrypts files in place, so preventive controls like firewalls or antivirus may fail against new variants, but offline or immutable backups preserve a clean copy. The key is that backups must be isolated (offline, air-gapped, or immutable) to prevent the ransomware from encrypting them too.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall
Why it's wrong here
A firewall filters inbound and outbound traffic by rule, but it stores no file copies and cannot reverse encryption already applied. It is tempting because blocking command-and-control traffic curtails the attack, which suits perimeter prevention rather than recovering encrypted data without paying.
- ✓
Regular backups
Why this is correct
Regular backups preserve an unencrypted copy of data offline, so files can be restored without the attacker's decryption key. This directly satisfies the recovery requirement, whereas antivirus, patching or firewalls may block initial infection but cannot restore data already encrypted by ransomware.
- ✗
Intrusion detection system
Why it's wrong here
An IDS detects and alerts on malicious network or host activity, but it holds no copy of the encrypted files, so it cannot restore them. It is tempting because detecting the intrusion early limits spread, which suits identifying an attack in progress rather than recovering data afterwards.
- ✗
Antivirus software
Why it's wrong here
Antivirus may quarantine the ransomware binary, yet once files are encrypted it cannot decrypt them without the attacker's key. It is tempting because signature-based detection blocks known malware, which suits preventing initial execution rather than restoring data after encryption has occurred.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Antivirus
Antivirus is software that detects, prevents, and removes malicious software (malware) from a computer or network.
Key term
Security control
A security control is a safeguard or countermeasure designed to protect the confidentiality, integrity, and availability of information systems and data.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.