ISC2 CC Business Continuity, DR & Incident Response Practice Question
An organization experiences a ransomware attack that encrypts critical file servers. The backups are stored on a separate network segment but are also encrypted. The incident response team suspects the attacker compromised the backup system using stored credentials. Which best practice should have been implemented to prevent this?
⚠ Common exam trap
ISC2 often tests the distinction between preventive controls that stop the attack vector (MFA on access) versus controls that mitigate damage after compromise (air gaps, encryption, VLANs), leading candidates to choose network segmentation or encryption instead of addressing the credential theft directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable multi-factor authentication (MFA) on backup system access
Enabling multi-factor authentication (MFA) on backup system access would have prevented the attacker from using stored credentials to compromise the backup system. MFA requires an additional authentication factor beyond just a password or stored token, making credential theft or reuse insufficient for access. This directly addresses the attack vector described—stolen credentials—rather than relying solely on network segmentation or encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement air-gapped backups stored offline
Why it's wrong here
Air-gapped backups would prevent online encryption, but the scenario specifically mentions stored credentials were used; air-gapping does not address credential compromise directly.
- ✓
Enable multi-factor authentication (MFA) on backup system access
Why this is correct
MFA mitigates the risk of credential theft, as the attacker would need an additional factor to authenticate.
- ✗
Encrypt backup data at rest and in transit
Why it's wrong here
Encryption protects data confidentiality but does not prevent an attacker from deleting or encrypting backups if they gain access.
- ✗
Use a separate VLAN for backup traffic
Why it's wrong here
Network segmentation alone does not prevent an attacker who has already gained access to the backup system via stolen credentials.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Time-based One-time Password
A temporary, automatically generated code that changes every few seconds and is used as an extra layer of security when logging into an account.
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
About these practice questions
Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.