Courseiva
Security OperationshardMultiple ChoiceObjective-mapped

CISSP Security Operations Practice Question

An organization is recovering from a ransomware attack that encrypted critical servers. The backup strategy must ensure that the Recovery Point Objective (RPO) of 1 hour is met. Which backup method is MOST appropriate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Continuous data protection (CDP)

Continuous data protection (CDP) captures changes in real time, meeting a 1-hour RPO.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Continuous data protection (CDP)

    Why this is correct

    Continuous Data Protection (CDP) records every transaction and change as it occurs, effectively creating a continuous stream of recovery points. This granular approach allows an organization to restore data to any specific point in time, including moments immediately preceding a ransomware infection, thereby minimizing data loss to near zero. It directly addresses stringent Recovery Point Objectives (RPOs) by capturing every change, ensuring the most current data is always available for restoration.

  • Daily full backups

    Why it's wrong here

    Daily full backups capture a complete copy of all specified data once every 24 hours. While providing a baseline for recovery, this method inherently means that up to 24 hours of data generated between the last successful backup and the ransomware attack could be permanently lost. This significant data loss window often fails to meet modern Recovery Point Objectives (RPOs) for critical systems, making it an insufficient strategy for rapid and complete recovery from sophisticated attacks.

  • Weekly full backups with daily differentials

    Why it's wrong here

    This strategy involves a weekly full backup supplemented by daily differential backups, which only store changes since the last full backup. While more efficient than multiple full backups, recovery still requires restoring the last full backup followed by the latest differential, introducing complexity and potential for data loss up to 24 hours. This approach does not provide the necessary granularity to recover data precisely to the moment before a ransomware attack, thus failing to meet tight RPOs.

  • Snapshot every 4 hours

    Why it's wrong here

    Taking snapshots every four hours creates discrete recovery points at fixed intervals. In the context of a ransomware attack, this means that any data changes occurring within the four-hour window between the last snapshot and the infection event would be unrecoverable. This strategy directly violates a typical stringent Recovery Point Objective (RPO) requirement, as it guarantees a potential data loss of up to four hours, which is unacceptable for critical business operations.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.