ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
A financial services firm has activated its disaster recovery plan after a ransomware attack encrypted its primary data center. The incident response team has contained the attack, but the recovery team must restore operations. Which action should the recovery team take FIRST to ensure a successful restoration?
⚠ Common exam trap
The trap here is prioritizing speed over security by immediately restoring backups without first verifying they are malware-free.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Validate that the most recent backups are free from malware and can be restored.
In a ransomware recovery scenario, the first step is to ensure that backups are clean and restorable. Ransomware often targets backups, so validating their integrity prevents restoring malicious code. Once backups are verified, the team can proceed with restoration. This approach aligns with the incident response principle of containing and eradicating the threat before recovery. Skipping validation risks reinfection and further downtime.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately restore the most recent full backup to the primary data center.
Why it's wrong here
Restoring the most recent full backup without first verifying its integrity and malware-free status is risky. If the backup contains the ransomware, the restoration will reinfect the environment and potentially cause further damage. The recovery team must first validate the backup to avoid repeating the incident. Speed is important, but security and integrity take precedence to ensure a successful and safe restoration.
- ✗
Rebuild the primary data center from scratch using the original installation media.
Why it's wrong here
Rebuilding from scratch is a drastic measure that could take a long time and may not be necessary if backups are available and validated. It also does not address the immediate need to restore operations. The recovery team should first attempt to restore from clean backups, which is typically faster and less disruptive. Rebuilding from scratch would be a last resort if backups are unusable or compromised.
- ✗
Notify all customers about the data breach and provide credit monitoring services.
Why it's wrong here
Customer notification and credit monitoring are important after a data breach, but they are not the first priority for the recovery team. The immediate focus should be on restoring operations safely. Notification requirements may vary by regulation and should be handled by legal and communication teams in parallel. The recovery team's first action is to ensure that the restoration process does not reintroduce the threat.
- ✓
Validate that the most recent backups are free from malware and can be restored.
Why this is correct
Before restoring any data, the recovery team must ensure that the backups are not compromised. Ransomware often attempts to encrypt or delete backups, and restoring an infected backup could reintroduce the malware. Validating the integrity and cleanliness of backups is a critical first step to prevent reinfection. This aligns with incident response best practices, which emphasize verifying the trustworthiness of recovery sources before initiating restoration.
Go deeper
Related to this question
Learn chapter
Incident Response and Management
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.