Courseiva
Business Continuity, DR & Incident ResponsemediumMultiple ChoiceObjective-mapped

ISC2 CC Business Continuity, DR & Incident Response Practice Question

An organization experiences a ransomware attack that encrypts critical file servers. The backups are stored on a separate network segment but are also encrypted. The incident response team suspects the attacker compromised the backup system using stored credentials. Which best practice should have been implemented to prevent this?

⚠ Common exam trap

ISC2 often tests the distinction between preventive controls that stop the attack vector (MFA on access) versus controls that mitigate damage after compromise (air gaps, encryption, VLANs), leading candidates to choose network segmentation or encryption instead of addressing the credential theft directly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable multi-factor authentication (MFA) on backup system access

Enabling multi-factor authentication (MFA) on backup system access would have prevented the attacker from using stored credentials to compromise the backup system. MFA requires an additional authentication factor beyond just a password or stored token, making credential theft or reuse insufficient for access. This directly addresses the attack vector described—stolen credentials—rather than relying solely on network segmentation or encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement air-gapped backups stored offline

    Why it's wrong here

    Air-gapped backups would prevent online encryption, but the scenario specifically mentions stored credentials were used; air-gapping does not address credential compromise directly.

  • Enable multi-factor authentication (MFA) on backup system access

    Why this is correct

    MFA mitigates the risk of credential theft, as the attacker would need an additional factor to authenticate.

  • Encrypt backup data at rest and in transit

    Why it's wrong here

    Encryption protects data confidentiality but does not prevent an attacker from deleting or encrypting backups if they gain access.

  • Use a separate VLAN for backup traffic

    Why it's wrong here

    Network segmentation alone does not prevent an attacker who has already gained access to the backup system via stolen credentials.

About these practice questions

Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.