CISSP Security Operations Practice Question
An organization is recovering from a ransomware attack that encrypted critical servers. The backup strategy must ensure that the Recovery Point Objective (RPO) of 1 hour is met. Which backup method is MOST appropriate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Continuous data protection (CDP)
Continuous data protection (CDP) captures changes in real time, meeting a 1-hour RPO.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Continuous data protection (CDP)
Why this is correct
Continuous Data Protection (CDP) records every transaction and change as it occurs, effectively creating a continuous stream of recovery points. This granular approach allows an organization to restore data to any specific point in time, including moments immediately preceding a ransomware infection, thereby minimizing data loss to near zero. It directly addresses stringent Recovery Point Objectives (RPOs) by capturing every change, ensuring the most current data is always available for restoration.
- ✗
Daily full backups
Why it's wrong here
Daily full backups capture a complete copy of all specified data once every 24 hours. While providing a baseline for recovery, this method inherently means that up to 24 hours of data generated between the last successful backup and the ransomware attack could be permanently lost. This significant data loss window often fails to meet modern Recovery Point Objectives (RPOs) for critical systems, making it an insufficient strategy for rapid and complete recovery from sophisticated attacks.
- ✗
Weekly full backups with daily differentials
Why it's wrong here
This strategy involves a weekly full backup supplemented by daily differential backups, which only store changes since the last full backup. While more efficient than multiple full backups, recovery still requires restoring the last full backup followed by the latest differential, introducing complexity and potential for data loss up to 24 hours. This approach does not provide the necessary granularity to recover data precisely to the moment before a ransomware attack, thus failing to meet tight RPOs.
- ✗
Snapshot every 4 hours
Why it's wrong here
Taking snapshots every four hours creates discrete recovery points at fixed intervals. In the context of a ransomware attack, this means that any data changes occurring within the four-hour window between the last snapshot and the infection event would be unrecoverable. This strategy directly violates a typical stringent Recovery Point Objective (RPO) requirement, as it guarantees a potential data loss of up to four hours, which is unacceptable for critical business operations.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.