Courseiva
mediumMultiple Choice

ISC2 CC Practice Question: A company experiences a ransomware attack that…

A company experiences a ransomware attack that encrypts all files on a server. Which security control would MOST effectively allow recovery without paying the ransom?

⚠ Common exam trap

The trap is assuming antivirus or firewall 'prevents' ransomware well enough to avoid the need for recovery; the exam wants the control that enables restoration, which is backups.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Regular backups

Regular backups are the most effective control for recovering from ransomware because they allow restoration of data to a known-good state without paying the ransom. Ransomware encrypts files in place, so preventive controls like firewalls or antivirus may fail against new variants, but offline or immutable backups preserve a clean copy. The key is that backups must be isolated (offline, air-gapped, or immutable) to prevent the ransomware from encrypting them too.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Firewall

    Why it's wrong here

    A firewall filters inbound and outbound traffic by rule, but it stores no file copies and cannot reverse encryption already applied. It is tempting because blocking command-and-control traffic curtails the attack, which suits perimeter prevention rather than recovering encrypted data without paying.

  • ✓

    Regular backups

    Why this is correct

    Regular backups preserve an unencrypted copy of data offline, so files can be restored without the attacker's decryption key. This directly satisfies the recovery requirement, whereas antivirus, patching or firewalls may block initial infection but cannot restore data already encrypted by ransomware.

  • ✗

    Intrusion detection system

    Why it's wrong here

    An IDS detects and alerts on malicious network or host activity, but it holds no copy of the encrypted files, so it cannot restore them. It is tempting because detecting the intrusion early limits spread, which suits identifying an attack in progress rather than recovering data afterwards.

  • ✗

    Antivirus software

    Why it's wrong here

    Antivirus may quarantine the ransomware binary, yet once files are encrypted it cannot decrypt them without the attacker's key. It is tempting because signature-based detection blocks known malware, which suits preventing initial execution rather than restoring data after encryption has occurred.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.