Courseiva
easyMultiple ChoiceObjective-mapped

CCSP Practice Question: A cloud customer experiences a ransomware attack…

A cloud customer experiences a ransomware attack that encrypts data in an object storage bucket. The customer has versioning enabled on the bucket. How can the customer MOST effectively restore the data?

⚠ Common exam trap

ISC2 often tests the misconception that 'versioning' is only for preventing accidental deletion, when in fact it also enables recovery from overwrites (including ransomware encryption), and candidates may incorrectly assume that a decryption key or undelete feature is the primary recovery method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Restore the bucket to a previous version using the versioning feature

With versioning enabled on the object storage bucket, each object version is preserved. The correct approach is to restore the bucket to a previous, unencrypted version using the versioning feature, which effectively rolls back the data to its state before the ransomware encrypted the current versions. This avoids data loss and does not require decryption keys or bucket deletion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Delete the bucket and recreate it

    Why it's wrong here

    Deletes all data including versions.

  • Restore the bucket to a previous version using the versioning feature

    Why this is correct

    Versioning allows recovery of unencrypted versions.

  • Use the cloud provider's undelete feature for the encrypted objects

    Why it's wrong here

    No such feature; versioning is used.

  • Decrypt the objects using the ransomware decryption key

    Why it's wrong here

    Not available.

About these practice questions

Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.