Courseiva
Security Principles →hardMultiple Choice

ISC2 CC Security Principles Practice Question

A security analyst is evaluating the risk of a ransomware attack on a company's file server. The analyst determines that the likelihood of an attack is high and the potential impact is severe. However, the company has a reliable offline backup that can restore all data within four hours. How should the analyst classify the risk?

⚠ Common exam trap

The trap here is ignoring the mitigating effect of the backup and rating risk solely on likelihood and impact, or conversely, assuming the backup eliminates risk entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The risk is moderate because the backup reduces the impact, but likelihood remains high.

The analyst should classify the risk as moderate. Although the likelihood of a ransomware attack is high, the reliable offline backup significantly reduces the potential impact by enabling rapid restoration. Risk is the combination of likelihood and impact; with high likelihood but reduced impact, the overall risk is moderate. This reflects the residual risk after considering the mitigating control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The risk is low because the backup can restore data quickly.

    Why it's wrong here

    The backup reduces impact but does not eliminate the risk entirely. There may still be downtime, loss of productivity, and potential data leakage during the attack. The likelihood remains high, and some impact persists. Thus, classifying the risk as low overstates the effectiveness of the backup and underestimates residual risk.

  • ✓

    The risk is moderate because the backup reduces the impact, but likelihood remains high.

    Why this is correct

    Risk is a function of likelihood and impact. Here, likelihood is high, but the backup reduces the impact from severe to moderate. The residual risk is therefore moderate. This classification acknowledges both the high likelihood and the mitigating effect of the backup, resulting in a balanced risk rating that reflects the remaining exposure.

  • ✗

    The risk is eliminated because the backup ensures full recovery.

    Why it's wrong here

    Risk cannot be eliminated solely by a backup. Backups may fail, be incomplete, or be compromised. Additionally, the attack could cause other damages such as reputational harm or temporary loss of service. The backup mitigates impact but does not remove the risk entirely. Therefore, stating that risk is eliminated is incorrect.

  • ✗

    The risk is high because the likelihood and impact are both high.

    Why it's wrong here

    While likelihood and impact are high, risk assessment must also consider existing controls that mitigate impact. The reliable offline backup significantly reduces the potential impact by enabling quick restoration. Therefore, classifying the risk as high solely based on likelihood and impact ignores the mitigating control, leading to an inaccurate risk rating.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.